Abstract: A method of mitigating an amplification attack by a controller node on an and system in a network, the method comprising: Detecting one or more candidate attack request packets received by an intermediary node in the network: and Limiting response traffic of response packets communicated from the intermediary node to the end system by a credit derived from the detected candidate attack request packets communicated from the controller node to the intermediary node, wherein each response packet transmitted from the intermediary node to the end system draws on the credit.