A Slow Rate Denial-of-Service Attack Against HTTP/2

Yihang Zhang, Yijie Shi · 2018

HTTP/2 is the second major version of the HTTP protocol published by the IEIF. One of its purposes is to make more efficient use of the transmission efficiency of the TCP protocol. However, while improving efficiency, the emergence of the HTTP/2 protocol has also made attackers have another option to attack Web servers. This paper proposes a slow denial-of-service attack named zAttack against the HTTP/2 protocol, which sends specific request packets through a malicious client to cause the server to wait, continuously consume server resources and finally cause a denial-of-service attack. This paper uses a number of popular web servers to test this attack. The test results show that mainstream web servers that support the HTTP/2 protocol are vulnerable to this attack.

Read the paper · More papers on PaperTik