DocumentCode
3668568
Title
Low-Rate Denial-of-Service Attacks against HTTP/2 Services
Author
Erwin Adi;Zubair Baig;Chiou Peng Lam;Philip Hingston
Author_Institution
Sch. of Comput. &
fYear
2015
Firstpage
1
Lastpage
5
Abstract
HTTP/2 is the second major version of the HTTP protocol approved by the Internet Engineering Steering Group (IESG). Although the semantics of how messages are exchanged between clients and servers remains the same, the protocol demands more computing power than its predecessor, HTTP/1.1. Hence HTTP/2 is more vulnerable to Denial-of-Service (DoS) attacks. A variant of the DoS type of attack is to send low-rate traffic that contains resource-hungry instructions, to a victim node. This low-rate DoS attacks can succeed only if the victim hosts an application that consumes large-scale computing resources once activated. With the introduction of HTTP/2, we showed that the attack can be launched at the protocol level by sending low-rate HTTP/2 packets to a web server. To the best of our knowledge, no study has been done on how DoS attacks can be launched against HTTP/2 services. Results obtained prove the effect of a low-rate DoS attack against HTTP/2 services.
Keywords
"Computer crime","Protocols","Computers","Web servers","Delays"
Publisher
ieee
Conference_Titel
IT Convergence and Security (ICITCS), 2015 5th International Conference on
Type
conf
DOI
10.1109/ICITCS.2015.7292994
Filename
7292994
Link To Document