An ICMP flood overwhelms a target with echo request traffic, aiming to saturate available bandwidth or exhaust the CPU cycles spent generating replies. Unlike protocol attacks, the goal is raw volume.
Written for business and infrastructure decision-makers, not protocol engineers.
ICMP echo requests — the traffic behind the everyday "ping" command — are normally lightweight diagnostic traffic. During an ICMP flood, attackers generate far more of it than any legitimate diagnostic use would ever require, consuming bandwidth and processing capacity regardless of whether any individual packet looks suspicious.
Answering one call is trivial. Answering thousands per second, continuously, leaves no capacity for anything else. An ICMP flood applies the same pressure to network links and hosts that must process every echo request they receive.
Availability risk that belongs in business-continuity planning.
Availability risk that belongs in business-continuity planning.
Availability risk that belongs in business-continuity planning.
Availability risk that belongs in business-continuity planning.
ICMP-based flooding, including amplification variants like Smurf attacks, has been used against networks since the 1990s. It remains relevant because ICMP traffic is rarely blocked outright — doing so would break legitimate diagnostics — which leaves volume-based filtering as the practical defense.
Attacks against one customer can become an infrastructure and service-quality issue.
Availability, latency and shared network resources are immediately visible to end users.
If users cannot connect, they cannot transact, work or consume the service they pay for.
NeuroWall runs a dedicated ICMP module, benchmarked sustaining ~83K PPS in the same 375,000-policy test as its SYN flood module, enforcing per-source and aggregate rate ceilings while normal diagnostic traffic continues to pass.
Book a Demo →An ICMP flood sends a very high rate of ICMP echo request (ping) traffic at a target, aiming to saturate bandwidth or exhaust the CPU cycles needed to generate replies.
No. A ping of death exploits malformed oversized packets to crash a system. An ICMP flood relies purely on volume of otherwise-valid traffic.
ICMP carries important diagnostic and network-health signaling. Blocking it entirely can break legitimate troubleshooting and some path-discovery mechanisms, so rate control is preferred over an outright block.
It can be. When many distributed sources generate the traffic simultaneously, it is a distributed denial-of-service attack.
Yes. NeuroWall enforces per-source and aggregate ICMP rate limits as part of its DDoS protection capabilities.