Defer No Time, Delays have Dangerous Ends: Slow HTTP/2 DoS Attacks into the Wild
Nikhil Tripathi, Abhijith Kalayil Shaji · 2022
Slow Rate DoS attacks intend to prevent the legitimate clients from accessing the target application (web, mail, etc.) running over the victim server. These attacks target application layer protocols, and HTTP/1.1 is one of the most studied protocols against Slow Rate DoS attacks. HTTP/2, the successor of HTTP/1.1, is also found to be vulnerable to these attacks. However, the impact of these attacks on real HTTP/2 servers on the Internet has not been studied yet. In this preliminary work, we test the behaviour of Alexa top 500K websites on the Internet against Slow Rate DoS attacks. We first conduct experiments to find the websites that serve web content over HTTP/2. Subsequently, we test their web servers against the Slow Rate DoS attacks and furnish the results. We observe that several HTTP/2 servers on the Internet are vulnerable to these attacks, thereby, advocate developing a robust real-time detection strategy. Towards the end of the paper, we also discuss some possible defense mechanisms to counter the attacks.