HomeSecurityNew DoS attack on HTTP/2 protocol brings down servers

New DoS attack on HTTP/2 protocol brings down servers

Newly discovered vulnerabilities in the HTTP/2 protocol, known as “CONTINUATION Flood“, can lead to denial of service (DoS) attacks, causing web servers to crash with a single TCP connection in some implementations.

See also: New 'Loop DoS' attack affects hundreds of thousands of systems

HTTP/2 DoS attack

HTTP/2 is an update to the HTTP protocol standardized in 2015, designed to improve web performance by introducing binary frames for efficient data transmission, allowing multiple requests and responses over a single connection, and header compression to reduce overhead.

The new CONTINUATION Flood vulnerabilities were discovered by researcher Barket Nowotarski, who says they are related to the use of HTTP/2 CONTINUATION, which are not properly restricted or checked in many implementations of the protocol, resulting in DoS attacks.

HTTP/2 messages include header and trailer sections that are serialized into blocks. These blocks can be split into multiple frames for transmission, with CONTINUATION frames used to wrap the stream.

The omission of proper frame checks in many implementations allows malicious actors to potentially send an extremely large number of frames, simply without setting the “END_HEADERS” flag, resulting in servers crashing due to lack of memory or CPU exhaustion as these frames are processed.

See also: Cisco fixes critical vulnerabilities in IOS XR software

New DoS attack on HTTP/2 protocol brings down servers

The researcher warned that out-of-memory conditions could lead to server malfunctions using a single TCP HTTP/2 connection in some implementations.

“Out of Memory cases are probably the most boring but also the most serious. There is nothing special about it: no strange logic, no interesting competition problems, etc.,” Nowotarski explains.

“Implementations that allow OOM simply did not limit the size of the header list created using CONTINUATION frames.“

A recently published CERT Coordination Center (CERT-CC) alert lists several CVE identifiers corresponding to different HTTP/2 implementations vulnerable to these attacks.

See also: SonicWall: Thousands of firewalls vulnerable to DoS and RCE attacks

What are the techniques for protecting against attacks DoS

One of the most popular techniques for protecting against DoS attacks, such as the one in the HTTP/2 protocol, is to identify them. This can be done by monitoring network traffic and looking for unusual patterns or spikes in traffic . Using a DoS protection system is also an important technique. These systems are designed to absorb and deal with DoS traffic, protecting the network from overload. Using a rate limiting system can also be useful. IP spoofing countermeasures can also be effective. These include verifying the source of IP addresses and blocking addresses that appear to be spoofed.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS