Catalogued but Dormant: A Honeypot Measurement of Residual Memcached Amplification Abuse
Observing scan and test, but not execute, on a public Memcached honeypot
M. Hájek (TU Delft - Electrical Engineering, Mathematics and Computer Science)
Harm Griffioen – Mentor (TU Delft - Electrical Engineering, Mathematics and Computer Science)
Mitchell Olsthoorn – Graduation committee member (TU Delft - Electrical Engineering, Mathematics and Computer Science)
More Info
expand_more
Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.
Abstract
The 2018 Memcached amplification attacks set the public DDoSrecord, after which UDP wasdisabled by default and port 11211 widely firewalled. Yet tens of thousands of misconfigured servers remain reachable, leaving open the question of whether, and how, attackers still exploit this residual surface. We address it with a custom, safety-bounded Memcached honeypot deployed on 16 public IPv4 addresses for 22 days. Over the window it recorded 4,261 packets from 465 sources. Traffic is dominated by stats reconnaissance bearing recognisable tooling fingerprints, and 23 sources swept the full address block: the scan and test phases of the established workflow are clearly present. The execute phase, however, never materialised: no source populated the cache, empirical amplification capped at ≈13×, and the only abuse-related traffic was neutralised. The honeypot egressed just 277 KiB in total. Memcached today behaves as a catalogued but dormant amplifier: continuously enumerated and re-measured, but rarely weaponised.