99% liklihood is that your box is being used as a node in a DDoS attack called a DNS amplification attack. Probably in IP > DNS you have "allow remote requests" enabled, and in firewall filter, your input chain does not have a default "block all" rule, or else has a rule which e...