
October 15, 2014 Akamai Warns of UPnP Devices Used in DDoS Attacks
Akamai Contacts Rob Morton
Media Relations
617-444-3641
rmorton@akamai.com
or Tom Barth
Investor Relations
617-444-7130
tbarth@akamai.com
Four million Universal Plug and Play devices may be vulnerable to use by attackers
Fake requests to UPnP devices can elicit DDoS traffic to a target
Advisory explains need for vendor and community action
CAMBRIDGE, Mass. - October 15, 2014 - Akamai Technologies, Inc. (NASDAQ: AKAM), the leading provider of cloud services for delivering, optimising and securing online content and business applications, today released, through the companys Prolexic Security Engineering & Response Team (PLXsert), a new cybersecurity threat advisory. The advisory alerts the security community, device vendors, Internet service providers and enterprises to the risk of massive distributed denial of service (DDoS) attacks involving Universal Plug and Play (UPnP) devices. The advisory is available for download from Prolexic (now part of Akamai) at www.prolexic.com/ssdp.
PLXsert has observed the use of a new reflection and amplification DDoS attack that deliberately misuses communications protocols that come enabled on millions of home and office devices, including routers, media servers, web cams, smart TVs and printers. The protocols allow devices to discover each other on a network, establish communication and coordinate activities. DDoS attackers have been abusing these protocols on Internet-exposed devices to launch attacks that generate floods of traffic and cause website and network outages at enterprise targets.
Malicious actors are using this new attack vector to perform large-scale DDoS attacks. PLXsert began seeing attacks from UPnP devices in July, and they have become common, said Stuart Scholly, senior vice president and general manager, Security Business Unit, Akamai. The number of UPnP devices that will behave as open reflectors is vast, and many of them are home-based Internet-enabled devices that are difficult to patch. Action from firmware, application and hardware vendors must occur in order to mitigate and manage this threat.
PLXsert found 4.1 million Internet-facing UPnP devices are potentially vulnerable to being employed in this type of reflection DDoS attack - about 38 percent of the 11 million devices in use around the world. PLXsert will share the list of potentially exploitable devices to members of the security community in an effort to collaborate with cleanup and mitigation efforts of this threat.
These attacks are an example of how fluid and dynamic the DDoS crime ecosystem can be, explained Scholly. Malicious actors identify, develop and incorporate new resources and attack vectors into their arsenals. Its predictable that they will develop, refine and monetize these UPnP attack payloads and tools in the near future.
Get the SSDP Reflection Threat Advisory to learn more
PLXsert replicated an attack of this type in a lab environment, demonstrating how attackers produce reflection and amplification DDoS attacks using UPnP-enabled devices. In the advisory, PLXsert shares its analysis and details, including:
How the SSDP protocol and SOAP requests are used in reflection attacks
Two example DDoS tools used to scan for vulnerable devices and launch attacks
Details of an observed attack campaign
Geographical distribution of UPnP devices involved in attacks
Top 10 most common headers in UPnP response payloads
Recommended system hardening and community action
DDoS mitigation
A complimentary copy of the threat advisory is available for download at www.prolexic.com/ssdp.
About Akamai
Akamai is the leading provider of cloud services for delivering, optimising and securing online content and business applications. At the core of the Companys solutions is the Akamai Intelligent Platform , providing extensive reach, coupled with unmatched reliability, security, visibility and expertise. Akamai removes the complexities of connecting the increasingly mobile world, supporting 24/7 consumer demand, and enabling enterprises to securely leverage the cloud. To learn more about how Akamai is accelerating the pace of innovation in a hyperconnected world, please visit www.akamai.com or blogs.akamai.com, and follow @Akamai on Twitter.
Top
Most recent headlines
11/12/2025
Dalet, a leading provider of cloud-native, end-to-end media workflow solutions, ...
05/12/2025
NEW YORK Iris, the new cloud-connected camera control platform, has officially launched with features that turn virtually any PTZ camera into a software-connect...
05/12/2025
HOLLYWOOD, Calif. Netflix announced today that it has entered into an agreement to acquire the assets of Warner Bros. for $82.7 billion....
05/12/2025
NEW YORK Iris, the new cloud-connected camera control platform, has officially launched with features that turn virtually any PTZ camera into a software-connect...
05/12/2025
WASHINGTON The Federal Communications Commission has approved AT&T's $1.02 billion acquisition of spectrum from UScellular in a decision that was issued sho...
05/12/2025
The Best Coldplay Songs: 21 Tracks That Shoot for the Stars From Yellow to Viva La Vida, Fix You to Paradise, this playlist goes back to the start.
December ...
05/12/2025
Zafris Lecture Series Brings Nabil Ayers to Berklee The 32nd annual James G. Zafris Distinguished Lecture series was held on Thursday, November 13 with guest ...
05/12/2025
The Grinch steals the spotlight as the theme for The Late Late Toy Show 2025
Tune in tonight at 9:35pm on RT One and worldwide on RT Player
#LateLateToyShow...
05/12/2025
RT Announces New Presenters of Flagship News Programmes
New RT Six One News co-presenter Tommy Meskill
Sarah McInerney & Justin McCarthy join Morning Ir...
04/12/2025
ToolsOnAir Blackmagic Design HyperDeck Event Presets for just:in mac pro 2025 & ...
04/12/2025
ToolsOnAir AJA Ki Pro Event Presets for just:in mac pro 2025 & just:in linux
More Details:Starting with version 5.5, both just:in mac pro and just:in linux sol...
04/12/2025
Wangu Kanuri from Kenya and Godwin Asediba from Ghana are two of this years finalists for Thomsons Young Journalist of the Year Award. The pair are runners-up i...
04/12/2025
SVG Sit-Down: ProximaVision's Claudio Lisman on Why Tethered Drones Could Be...
04/12/2025
SVG Campus Shot Callers: Imry Halevi, Senior Associate Director of Athletics, Co...
04/12/2025
Platinum White Paper: LiveU Lightweight Sports Production: A Step Change in Spor...
04/12/2025
London to Riyadh: DAZN brings the boxing glamour to new production levels for Be...
04/12/2025
Analysis: Paramount bets on the battering ram' with Champions League play By Callum McCarthy, Editor-at-Large
Tuesday, December 2, 2025 - 10:12
Print ...
04/12/2025
Space City Home Network Launches SCHN DTC App for Astros and RocketsThe Rockets and Astros were previously the lone NBA and MLB teams without a DTC appBy Jason...
04/12/2025
SVG Summit 2025 Preview: Content Workflows Workshop Spotlights Evolution of Spor...
04/12/2025
New Sponsor Spotlight: Geotech's Patrick Wambold On the Unreal Engine Revolu...
04/12/2025
Curt Gowdy Jr. - Master Storyteller, Nationally and RegionallyBy Jason Dachman, Editorial Director, U.S.
Thursday, December 4, 2025 - 1:52 pm
Print This Sto...
04/12/2025
(L-R) Rebecca Lichtenfeld, Mohammadreza Eyni, Sara Khaki, and Judith Helfand att...
04/12/2025
SBS launches Future Frames initiative to support emerging First Nations video ed...
04/12/2025
Coronal mass ejections caused by eruptions on the surface of the sun can have fa...
04/12/2025
Gracenote Content Connect enables media ecosystem to precisely align ad campaigns and programming based on rich content signals
NEW YORK - December 4, 2025 - N...
04/12/2025
Lightware, a global specialist in AV connectivity, is looking back on a year defined by new advancements, strong collaboration and continued growth. Across the ...
04/12/2025
Riedel Communications today announced a new partnership with Haivision, a leading global provider of mission-critical, real-time video networking and visual col...
04/12/2025
Harmonic (NASDAQ: HLIT) and Normann Engineering today announced a major milestone in their strategic collaboration, celebrating 20 successful broadband deployme...
04/12/2025
Creative software developer Foundry today announced Mari 7.5, the latest iteration of its artist-friendly paint toolset that can handle large, detailed assets w...
04/12/2025
Professional Wireless Systems (PWS), a leading provider of wireless audio solutions and RF management, was on site at Dreamforce 2025 in San Francisco providing...
04/12/2025
LTN's purpose-built IP video network brings all-movie diginet to over 100 stations and streaming platforms in just three months while eliminating satellite ...
04/12/2025
Bitmovin, the leading provider of video streaming solutions, today announced a strategic partnership with ThinkAnalytics, the global leader in AI-powered data a...
04/12/2025
The HELM, a global expert in cinematic live broadcast and high-end production workflows, has signed a partnership agreement with Keslow Camera, one of North Ame...
04/12/2025
At ISE 2026, LiveU will showcase its expanded IP-video EcoSystem, enabling broadcasters, sports, production companies and pro-AV professionals to share their st...
04/12/2025
Since the beginning of commercial television, advertising has been a key part of broadcasting. Over the years, the technology for inserting ads into programs ha...
04/12/2025
MUNICH and MILAN Warner Bros. Discovery said HBO Max is expanding into Germany, Italy, Austria, Switzerland, Luxembourg and Liechtenstein on Jan. 13, 2026, and ...
04/12/2025
SAN FRANCISCO AudioShake has launched its first streaming-capable software development kits (SDKs) designed specifically for real-time music detection and copyr...
04/12/2025
NASHVILLE The mobile and REMI production company TNDV has announced that it headed south into Mexico to live-produce the three-day 2025 Zane Grey Championship P...
04/12/2025
BURBANK, Calif. Hollywood Professionals Association Executive Director Phil Kubel has stepped down from the organization to pursue new opportunities, the group ...
04/12/2025
WASHINGTON The Federal Communications Commission said it has closed 2,048 inactive proceedings, the largest number of dormant dockets ever terminated in a singl...
04/12/2025
A new tech blog from Netflix highlights the importance of the AV1 open video codec, which now powers about 30% of the platform's streaming and discusses a v...
04/12/2025
Following today's EBU Winter General Assembly in Geneva at which Israel's participation in the 2026 Eurovision Song Contest was confirmed, RT 's pos...
04/12/2025
Thursday 4 December 2025
Sky set to co-produce the story behind the world's most famous whale
Image Credit - Free Willy Keiko Foundation
Sky will co-pro...
04/12/2025
Thursday 4 December 2025
Sky Original documentary Murder at the Post Office to ...
04/12/2025
Back to All News
Hugo Silva, Leonor Watling, Esther Acebo and Gorka Otxoa Star ...
04/12/2025
Back to All News
Step Inside the World of Troll 2: VFX Breakdown Featuring Dire...
04/12/2025
OBJECT MATRIX
OverviewObject Matrix
OM Cloud
Quattro
SWARMOverviewSwarmSingle Node Swarm
Ngenea
Pixstor
Swarm Support
Object Matrix Support
Pixstor & N...
04/12/2025
FOX Advertising Announces Plans for 2026 Upfront Presentation Annual Presentation for Advertisers to Take Place Monday, May 11 at New Location, the Historic N...
04/12/2025
Developers, researchers, hobbyists and students can take a byte out of holiday s...
04/12/2025
The ninth series of Dancing with the Stars returns to screens in early
2026 and will be proudly sponsored by Hyundai
Filling our Sunday evenings with glitz an...