ICMP Attack

The attacker broadcasts a large numbers of Internet Control Message Protocol (ICMP) packets with the intended victim's spoofed source IP to the network. Most devices on the network will (by default) respond to this by sending a reply to the source IP address. If the number of machines on the network that receive and respond to these packets is very large, the victim's computer will be flooded with traffic. This can slow down the victim's computer to the point where it becomes impossible to work. ICMP datagram can also be used to start an attack via ping. Attackers use the ping command to construct oversized ICMP datagram to launch the attack.