---
title: "Blocked attacks"
sidebar_label: "Blocked attacks"
description: "How to view the history of attacks mitigated by Selectel basic protection"
sidebar_position: 2
---

import {CustomTable} from '@selectel/docux/components'
import Formbricks from '@theme/MDXComponents/Formbricks'

# Blocked attacks

You can view the history of DDoS attacks blocked by [Selectel protection](/anti-ddos/ddos-selectel.mdx) in the Control panel.

Selectel protection operates at the network and transport layer (L3-L4). If your monitoring systems have detected an application-layer (L7) attack or other malicious activity, immediately contact the [support service](https://my.selectel.ru/tickets/create/) and activate [additional protection](/anti-ddos/about-anti-ddos.mdx#select-additional-protection).

## View attack history \{#view-attack-history}

1. In the [Control panel](https://my.selectel.ru/network/blocktools/attacks), on the top menu, click **Products** and select **Network Incidents**.
2. Open the **Blocked attacks** tab. For each attack, the attacked network, attack period, and the response from the protection system are indicated:

   * `block` — suspicious traffic was fully dropped;
   * `redirect` — suspicious TCP traffic was filtered, only legitimate requests were passed;
   * `detect` — suspicious traffic was detected but not dropped. A new attack detection rule is being tested in the system, or traffic blocking is disabled for the IP address.
3. To view detailed information about an attack, including the [attack type](#attack-types), its rate, intensity, total number of packets sent, and volume, click the network IP address in the attack row.
4. Optional: if you observe a prolonged attack that disrupts or limits service availability, additionally protect the attacked server:

   * change the server IP address;
   * activate [additional protection](/anti-ddos/about-anti-ddos.mdx#select-additional-protection).

## Attack types \{#attack-types}

<CustomTable>
  <table>
    <thead>
      <tr>
        <th />

        <th>Description</th><th>Attack target</th>
      </tr>
    </thead>

    <tbody>
      <tr>
        <th>UDP flood to service DST port 565 limited</th><td>UDP traffic attack on destination port 565 Whoami</td>

        <td>
          <ul>
            <li>Exhaustion of the bandwith and computing resources of the attacked host;</li><li>denial of service for the attacked application</li>
          </ul>
        </td>
      </tr>

      <tr>
        <th>UDP flood to service DST port 1194 limited</th><td>UDP traffic attack on destination port 1194 OpenVPN</td><td>Exhaustion of the bandwidth and computing resources of the attacked host, denial of service for the attacked application</td>
      </tr>

      <tr>
        <th>NTP Monlist Response</th><td>Reflected and amplified UDP traffic attack from source port 123 (NTP Monlist response vulnerability)</td><td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>SSDP Reflection</th><td>Reflected and amplified UDP traffic attack from source port 1900 (SSDP and UPnP protocol vulnerability)</td><td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>Empty UDP data</th><td>Attack on client IP with empty UDP datagrams (Empty UDP Flood)</td><td>Increased victim network utilization</td>
      </tr>

      <tr>
        <th>Memcache</th><td>Reflected and amplified UDP traffic attack from source port 11211 (Memcache vulnerability)</td><td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>SSRP Reflection</th><td>Reflected and amplified UDP traffic attack from source port 1434 SSRP (SQL Server Resolution Protocol)</td><td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>WSD Reflection</th><td>Reflected and amplified UDP traffic attack from source port 11211 (Memcache vulnerability)</td><td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>Net Assistant Reflection</th><td>Reflected and amplified UDP traffic attack from source port 3283 (Apple Network Assistant vulnerability)</td><td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>LowShadyPorts/Reflection flood to server limited</th>

        <td>
          Reflected and amplified UDP traffic attack from source ports:

          <ul>
            <li>19 CHARGEN (Character Generator);</li><li>111 SUNRPC (Sun Remote Procedure Call);</li><li>137 NETBIOS-NS (NetBIOS Name Service);</li><li>161 SNMP (Simple Network Management Protocol);</li><li>389 LDAP (Lightweight Directory Access Protocol);</li><li>520 ROUTER (used by routing protocols, e.g., RIP)</li>
          </ul>
        </td>

        <td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>Custom UDP amplifications</th>

        <td>
          Reflected and amplified UDP traffic attack from source ports:

          <ul>
            <li>37810 DHCPDiscover for DVR devices;</li><li>10074 TP240PhoneHome (Mitel systems);</li><li>37020 SADP (Hikvision)</li>
          </ul>
        </td>

        <td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>Custom UDP amplifications3</th><td>Reflected and amplified UDP traffic attack from source port 37021 SADP (Hikvision)</td><td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>Query Response/DNS query response reflection flood to server limited</th>

        <td>
          DNS Response traffic attack from public DNS servers with source port 53 UDP DNS and flags set from the DNSSEC extension:

          <ul>
            <li>DNS Signature;</li><li>DNS Signature Recursive</li>
          </ul>
        </td>

        <td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>Source Port 53/UDP source port 53 reflection flood to server limited</th><td>Reflected and amplified UDP traffic attack from source port 53 UDP DNS</td><td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>Source Port 4500/UDP source port 4500 reflection flood to server limited</th><td>Reflected and amplified UDP traffic attack from source port 4500</td><td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>Any Source Port/UDP source port reflection flood to server limited</th><td>High volume UDP traffic attack from a specific source port to any client IP destination port</td><td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>RST/TCP RST reflection flood to server limited</th><td>TCP traffic attack with TCP RST flag set from a specific source port to any client IP destination port</td>

        <td>
          <ul>
            <li>Exhaustion of the attacked host's computing resources;</li><li>disruption of TCP connections on the attacked host (or group of hosts)</li>
          </ul>
        </td>
      </tr>

      <tr>
        <th>SYN/ACK/TCP SYN/ACK reflection flood to server limited</th><td>TCP traffic attack with TCP RST flag set from a specific source port to any client IP destination port</td><td>Exhaustion of network and computing resources of the attacked host</td>
      </tr>

      <tr>
        <th>PSH/ACK/TCP PSH/ACK reflection flood to server limited</th><td>TCP traffic attack with TCP RST or TCP PSH flags set from a specific source port to any client IP destination port</td><td>Exhaustion of the attacked host's computing resources</td>
      </tr>

      <tr>
        <th>Failed Reflectors/ICMP Server flood to server limited</th><td>Attack on a client host with a large volume of response ICMP traffic from public servers, triggered by attacker-sourced specific requests to public servers for UDP port reachability, but with the source address spoofed to the client's</td><td>Exhaustion of bandwidth and computing resources of the attacked host</td>
      </tr>

      <tr>
        <th>UDP flood to service DST port 53 limited</th><td>UDP traffic attack on destination port 53 DNS</td>

        <td>
          <ul>
            <li>Exhaustion of bandwidth and computing resources of the attacked host;</li><li>denial of service for the attacked application</li>
          </ul>
        </td>
      </tr>

      <tr>
        <th>Any Destination Port/UDP service flood to a server port limited</th><td>Attack with high volume UDP traffic to any custom victim port</td>

        <td>
          <ul>
            <li>Bandwidth exhaustion;</li><li>denial of service for the attacked application</li>
          </ul>
        </td>
      </tr>

      <tr>
        <th>Any Type/ICMP/ICMPv6 service flood to server limited</th><td>Attack with custom ICMP traffic (including ICMPv6) of large volume on a specific client destination port</td><td>Exhaustion of bandwidth and computing resources of the attacked host</td>
      </tr>

      <tr>
        <th>SYN/TCP SYN to a server port limited</th><td>TCP traffic attack with TCP SYN flag set on a specific client IP destination port</td>

        <td>
          <ul>
            <li>Exhaustion of network and computing resources of the attacked host;</li><li>disruption of TCP connection establishment on the attacked host</li>
          </ul>
        </td>
      </tr>

      <tr>
        <th>RST/TCP RST to a server port limited</th><td>TCP traffic attack with TCP RST flag set on a specific client IP destination port</td>

        <td>
          <ul>
            <li>Exhaustion of the attacked host's computing resources;</li><li>disruption of TCP connections on the attacked host or group of hosts</li>
          </ul>
        </td>
      </tr>

      <tr>
        <th>PSH/ACK/TCP PSH/ACK service flood to a server port limited</th><td>TCP traffic attack with TCP RST/PSH flags set on a specific client IP destination port</td><td>Exhaustion of the attacked host's computing resources</td>
      </tr>

      <tr>
        <th>Any TCP/TCP to a server port limited</th><td>Attack with custom TCP traffic of large volume on a specific client port</td><td>Exhaustion of the attacked host's computing resources and bandwidth</td>
      </tr>

      <tr>
        <th>Fragment Under Attack/UDP server under attack fragment to server limited</th><td>Attack with fragmented UDP datagrams. Usually accompanies other types of UDP attacks</td><td>Bandwidth exhaustion</td>
      </tr>

      <tr>
        <th>Any Port/UDP server flood to server limited</th><td>Attack with custom UDP traffic of large volume cumulatively on any client port</td><td>Exhaustion of the attacked host's computing resources and bandwidth</td>
      </tr>

      <tr>
        <th>Any Type/ICMP server flood to server limited</th><td>Attacking large amounts of custom ICMP traffic, including ICMPv6, on any client destination port</td><td>Exhaustion of bandwidth and computing resources of the attacked host</td>
      </tr>

      <tr>
        <th>SYN/TCP SYN to server address limited</th><td>TCP traffic attack with TCP SYN flag set on any client IP destination port</td>

        <td>
          <ul>
            <li>Exhaustion of network and computing resources of the attacked host;</li><li>disruption of TCP connection establishment on the attacked host</li>
          </ul>
        </td>
      </tr>

      <tr>
        <th>RST/TCP RST to server address limited</th><td>TCP traffic attack with TCP RST flag set on any client IP destination port</td>

        <td>
          <ul>
            <li>Exhaustion of the attacked host's computing resources;</li><li>disruption of TCP connections on the attacked host or group of hosts</li>
          </ul>
        </td>
      </tr>

      <tr>
        <th>Any TCP/TCP to server address limited</th><td>Attack with custom TCP traffic of large volume in aggregate on any destination-port of the client</td><td>Exhaustion of network and computing resources of the attacked host and bandwidth</td>
      </tr>

      <tr>
        <th>IP protocol Any IP protocol server flood to server limited</th><td>Attack with custom IP traffic of large volume cumulatively by all transport protocols and all ports</td><td>Exhaustion of network and computing resources of the attacked host and bandwidth</td>
      </tr>

      <tr>
        <th>Flex Fragment/Flex matched IP fragment to destination IP under attack</th><td>Rule that defines blocking of IP packet fragments for hosts that are already under attack. Accompanies other attack types</td><td>—</td>
      </tr>

      <tr>
        <th>TCP FIN to a server port limited</th><td>TCP traffic attack with TCP FIN flag set on a specific client IP destination port</td>

        <td>
          <ul>
            <li>Exhaustion of network and computing resources of the attacked host;</li><li>disruption of the correct TCP connection establishment process on the attacked host</li>
          </ul>
        </td>
      </tr>

      <tr>
        <th>TCP FIN to server server address</th><td>TCP traffic attack with TCP FIN flag set in aggregate on any client IP destination port</td>

        <td>
          <ul>
            <li>Exhaustion of network and computing resources of the attacked host;</li><li>disruption of the correct TCP connection establishment process on the attacked host</li>
          </ul>
        </td>
      </tr>

      <tr>
        <th>TCP Any Flags</th><td>Attack with a large volume of traffic with any set of flags</td>

        <td>
          <ul>
            <li>Exhaustion of network and computing resources of the attacked host;</li><li>disruption of the correct TCP connection establishment process on the attacked host</li>
          </ul>
        </td>
      </tr>

      <tr>
        <th>UDP Fragment Server Smart-Rule</th><td>Attack with fragmented UDP datagrams</td><td>Bandwidth exhaustion</td>
      </tr>
    </tbody>
  </table>
</CustomTable>

<Formbricks />
