Amppot: Honeypot for Monitoring Amplification DDoS Attacks
Thank you for visiting us. We provide the observation results of Amppot, a honeypot for monitoring amplification DDoS Attacks [1].

News

2021/06/08
Amppot page is open!
We are happy to announce that our new Amppot page is open!

Amplification DDoS Observatory

These results are obtained by both high-interaction and agnostic Amppot in the last 7 days.

# Attacks by Protocols (World)

# Attacks by Protocols (Japan)

These results are obtained by both high-interaction and agnostic Amppot.

List of abused protocols observed by high-interaction Amppot (Only NTP, Memcached, Chargen, DNS, SNMP, SSDP, QotD are observed)

Service Port #Attack
List of abused protocols observed by agnostic Amppot (Agnostic Amppot listens on all UDP ports and returns random strings)

List of abused protocols observed by agnostic Amppot (Agnostic Amppot listens on all UDP ports and returns random strings)

Service Port #Attack
The table shows the number of attacks observed by agnostic Amppot over the last 7 days.

Reference

  • [1] Lukas Kramer, Johannes Krupp, Daisuke Makita, Tomomi Nishizoe, Takashi Koide, Katsunari Yoshioka, Christian Rossow, "AmpPot: Monitoring and Defending Amplification DDoS Attacks," Proceedings of the 18th International Symposium on Research in Attacks, Intrusions and Defenses (RAID'15).
  • [2] Takashi Koide, Daisuke Makita, Katsunari Yoshioka, Tsutomu Matsumoto, "Observation and Analysis of TCP-based Reflection DDoS Attacks Using Honeypot,” Posters of the 18th International Symposium on Research in Attacks, Intrusions and Defenses (RAID'15).