Isn't the 440 figure disingenuous? Surely you must count UDP/TCP header size, which would bring the value closer to 21/461 ~= 22. Still an interesting discovery. DDoS amplification is a security risk few people consider when developing applications.
Header size is 8-20 (without options) and if you read the article closelyer you'll see the total packet size was 480ish.
I dont know how you are getting 21/461 = 22 ?