Les articles de l’équipeExploiter un réseau

Types of IP spoofing attacks

Distinguish reflection, amplification and direct flooding, then see why ARP spoofing, DNS spoofing and botnets describe different things.

Sommaire

Three streams of blue and white envelopes converge from separate counters on one house and its overflowing blue mailbox.
Several services can send replies to an address that never asked for them. Reflection directs the burden towards an uninvolved recipient.

Not every attack described as “spoofing” changes an IP address, and not every flood of traffic uses forged addresses. The clearest way to understand an incident is to ask two questions: what information was falsified, and where did the traffic go?

Reflection: the reply goes to somebody else

Imagine requests sent to several services, all carrying one uninvolved person's address as the return address. The services send their replies to that person. The services are reflectors; the person receiving the unwanted replies is the victim.

In a network, a forged source IP can produce this effect when a service replies without first establishing that the sender can receive traffic at the claimed address. If a small request triggers a larger response, reflection also amplifies the traffic. RFC 5358 explains how open recursive DNS servers can be abused this way. Reflection is about the direction of replies; amplification is about their size. They are related, but not interchangeable.

Direct flooding: too much traffic reaches the target

A direct flood sends traffic to the target itself to consume connection state, processing capacity or bandwidth. Some floods use false source addresses. Others come from compromised devices using their actual addresses.

“Distributed denial of service”, or DDoS, describes an attack coming from multiple sources and disrupting availability. It does not mean that those sources must be forged. A botnet is a collection of compromised devices; it is not a separate kind of IP spoofing. Blocking false sources helps, but does not stop all DDoS traffic.

Impersonating a trusted source

A service may grant privileges because traffic appears to come from a familiar address. A forged source can be relevant to exploiting that trust, but it does not automatically establish a usable session. The attacker still faces the protocol's connection checks and any application authentication.

Descriptions sometimes distinguish “blind” attacks from attacks where the sender can observe the exchange. The useful distinction is visibility: an off-path attacker cannot normally see the replies, while an on-path attacker can observe traffic passing through their position. Being on the same local network is one possible situation, not the definition of all on-path attacks. Properly authenticated encryption still matters even when someone can observe packets.

ARP and DNS spoofing change different information

ARP connects an IPv4 address to a link-layer address on a local network. False ARP information can misdirect local delivery. DNS maps names to records, including addresses; false DNS answers can misdirect a name lookup. Neither is simply the act of changing an IP packet's source field.

These mechanisms can appear together in an incident, but they call for different controls. Local-network protections address false ARP mappings. DNSSEC validates signed DNS data where the trust chain is valid, as described in RFC 4033. Source filtering checks where IP traffic claims to originate. One control does not perform all three jobs.

Start with the traffic you actually see

Unrequested replies from many services suggest a reflection pattern. A busy server receiving direct requests may face a different problem. A surprising name lookup or local address mapping needs its own investigation. An address in a log is evidence to examine, not proof of a person's identity.

For the basic explanation, read what IP spoofing changes and what it does not. To turn these distinctions into a defence, continue to source validation, authentication and service protection.