首页> 外文会议>International Conference on Emerging Security Technologies >HTTP/2 Tsunami: Investigating HTTP/2 proxy amplification DDoS attacks
【24h】

HTTP/2 Tsunami: Investigating HTTP/2 proxy amplification DDoS attacks

机译:HTTP / 2海啸:研究HTTP / 2代理放大DDoS攻击

获取原文

摘要

Distributed Denial of Service (DDoS) attacks cause significant damage to computer systems by taking a system offline. Hypertext Transfer Protocol (HTTP), is the most commonly used protocol for web services. The HTTP protocol has recently received a major update to HTTP/2. This new protocol provides increased functionality, however this poses a threat from DDoS due to the larger attack surface. HTTP/2 implements novel compression techniques to reduce bandwidth, in this paper we explore this compression technology to providing understanding on its risk from DDoS, specifically in a HTTP/2 to HTTP/1 proxy deployment. We implement a testbed and measure the bandwidth to show that a amplification attack is possible which is comparable to the current largest amplification attacks.
机译:分布式拒绝服务(DDoS)攻击会使系统脱机,从而对计算机系统造成重大损害。超文本传输​​协议(HTTP)是Web服务最常用的协议。 HTTP协议最近收到了对HTTP / 2的重大更新。此新协议提供了增强的功能,但是由于攻击面更大,因此构成了DDoS的威胁。 HTTP / 2实现了新颖的压缩技术以减少带宽,在本文中,我们将探索这种压缩技术,以了解DDoS带来的风险,特别是在HTTP / 2到HTTP / 1代理部署中。我们实现了一个测试平台并测量了带宽,以表明可能发生与当前最大的放大攻击相当的放大攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号