All DDoS Definitions
DDoS Testing Definition

WS-Discovery Amplification

A WS-Discovery amplification attack is a Layer 4 reflection and amplification vector, one of the volumetric classes a thorough DDoS test is built to exercise. WS-Discovery (Web Services Dynamic Discovery) runs on UDP 3702 and lets devices such as IP cameras and printers announce themselves on a network. The attacker spoofs the victim's IP in a small probe to exposed WS-Discovery hosts, each of which replies with a much larger response. The amplification factor can reach several hundred times, and hundreds of thousands of devices sit reachable on the public internet.

WS-Discovery amplification: one probe, a fleet of reflectors exposed IoT fleet answering on UDP 3702 Attacker spoofs victim IP IP camera network printer DVR / NVR small spoofed probe many large replies Victim replies converge here Amplification can reach several hundred times the probe size hundreds of thousands of devices sit reachable on the public internet A test confirms no internal device answers UDP 3702 from outside, that ingress filtering blocks the spoofed sources, and where the link saturates. BlackNeuron
WS-Discovery amplification: one small probe to a fleet of exposed UDP 3702 IoT devices returns many large replies that converge on the victim

Why it matters in DDoS testing

WS-Discovery should never face the internet, yet misconfigured IoT fleets expose it constantly. Testing confirms that no internal device answers on UDP 3702 from outside, that ingress filtering blocks the spoofed sources, and where the saturated link first drops legitimate traffic. The reflection mechanics common to these vectors are detailed in Understanding DDoS Attack Vectors.