Four denial-of-service attacks at the packet level.
A SYN costs the sender 40 bytes and costs the server a half-open connection entry, held until the handshake times out. The table is finite and the traffic volume is small.
The TCP flags byte, with only SYN set.
Reflection, amplification and most volumetric floods depend on spoofed source addresses. IP does not verify the source. Only the network the packet leaves can filter it (BCP 38), and that network gets no direct benefit from doing so.
Amplification is the ratio of response size to request size. In both protocols here, fields in the request tell the server how much to send, and the attacker writes the request.
EDNS0 lifted DNS's 512-byte UDP limit. It is the field that allows large reflected answers.
A vendor-private NTP command that returns the last 600 clients the server talked to. It was used in the 400 Gbps attack of 2014.
Layer 7 attacks use well-formed requests and put the cost on the origin. The field that matters here is in a control frame, not in the data.
When each technique on the other tabs first appeared. Most follow the same pattern: a protocol reaches a large population of internet-facing hosts, someone finds a response much larger than its request, and the fix is to shrink the exposed population.