Work out ddos attack volume instantly with clear inputs, formula shown and shareable results.
Reflection and amplification attacks let a small botnet generate enormous volumes: the attacker sends spoofed requests to open services that reply with far larger responses. Amplification factors range from about 3 for DNS to over 50,000 for memcached, so ten gigabits of attacker bandwidth can become terabits at the victim. Packet rate matters separately, because many devices fail on packets per second long before bandwidth saturates.
Amplified volume
attack Gbps = sources x per-source Kbps x amplification / 1e6; pps = attack bits per second / (packet bytes x 8)
Firewalls, load balancers and routers have a packets-per-second ceiling set by their forwarding engine. A flood of small packets can exhaust it at a fraction of the link capacity.
By source-address validation (BCP 38) at network edges and by not exposing UDP services such as open DNS resolvers, NTP monlist, memcached and CLDAP to the internet.