HTTP/2 Tsunami: Investigating HTTP/2 Proxy Amplification DDoS Attacks

被引:0
作者
Beckett, David [1 ]
Sezer, Sakir [1 ]
机构
[1] Queens Univ Belfast, CSIT, Belfast, Antrim, North Ireland
来源
2017 SEVENTH INTERNATIONAL CONFERENCE ON EMERGING SECURITY TECHNOLOGIES (EST) | 2017年
关键词
DDoS; HTTP2; HPACK; Flood; Amplification; Attack; Apache; nghttp2; Nginx; Vulnerabilities;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Distributed Denial of Service (DDoS) attacks cause significant damage to computer systems by taking a system offline. Hypertext Transfer Protocol (HTTP), is the most commonly used protocol for web services. The HTTP protocol has recently received a major update to HTTP/2. This new protocol provides increased functionality, however this poses a threat from DDoS due to the larger attack surface. HTTP/2 implements novel compression techniques to reduce bandwidth, in this paper we explore this compression technology to providing understanding on its risk from DDoS, specifically in a HTTP/2 to HTTP/1 proxy deployment. We implement a testbed and measure the bandwidth to show that a amplification attack is possible which is comparable to the current largest amplification attacks.
引用
收藏
页码:127 / 132
页数:6
相关论文
共 12 条
[1]  
A. Networks, 2017, WORLDW INFR SEC REP
[2]   Distributed denial-of-service attacks against HTTP/2 services [J].
Adi, Erwin ;
Baig, Zubair A. ;
Hingston, Philip ;
Lam, Chiou-Peng .
CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2016, 19 (01) :79-86
[3]  
[Anonymous], 2016, HTTP 2 IN DEPTH AN T
[4]  
[Anonymous], 2015, RFC 7540 HYP TRANSF
[5]  
Baig Z., 2015, Security and Privacy in Communication Networks, V2015, P1
[6]  
IETF, 2015, RFC 7541 HPACK HEAD
[7]  
Incapsula, 2017, BREAK MIR BOTN
[8]  
Rossow C., 2014, 2014 NETW DISTR SYST
[9]  
Sherwood R., 2005, CCS 05 P 12 ACM C CO, P383, DOI DOI 10.1145/1102120.1102170
[10]   Evaluation of TFTP DDoS amplification attack [J].
Sieklik, Boris ;
Macfarlane, Richard ;
Buchanan, William J. .
COMPUTERS & SECURITY, 2016, 57 :67-92