Website Security & Threat Management
HTTP/2 Rapid Reset: deconstructing the record-breaking attack

HTTP/2 Rapid Reset: deconstructing the record-breaking attack

10/10/2023 · Lucas Pardue, Julien Desgats

What this post added

This post details the HTTP/2 Rapid Reset attack (CVE-2023-44487), a novel DDoS vector that exploits the HTTP/2 protocol's RST stream mechanism to generate massive request volumes with minimal botnet resources. It explains the HTTP/1.1 and HTTP/2 protocols, the stream lifecycle, and how the RST_STREAM frame can be abused. Cloudflare's mitigation strategies, including automated DDoS system enhancements and coordinated disclosure with Google and AWS, are discussed. The post also provides technical details on the attack's mechanics and the protocol features exploited.

Read the original post ↗