An ISP notifies an organization that its internal Memcached servers are actively participating in a massive DDoS attack against a third party. Which operational fix should the organization prioritize to stop this weaponization?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- ABlocking all outbound UDP would break legitimate services such as DNS and VoIP, a disproportionate fix for one misconfigured service.
- BMemcached amplification abuses spoofed UDP requests, so filtering inbound TCP SYN packets does not address it.
- CA CDN and WAF protect your own services from inbound attacks, but your servers are the attackers' reflectors, sending traffic to a third party.
- DCorrect: disabling Memcached's UDP interface and restricting access to trusted clients stops attackers from using the servers as amplifiers.