CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

Summary

Cybersecurity researchers have discovered two denial-of-service (DoS) attacks, dubbed "CDN Tsunami," that exploit the translation of HTTP/3 to HTTP/1.1 traffic by major content delivery networks (CDNs). These attacks can amplify low-bandwidth requests by up to 350 times against origin servers.

IFF Assessment

FOE

This article details new denial-of-service attack techniques that can significantly impact the availability of online services, posing a direct threat to defenders.

Severity

8.2 High (AI Estimated)

The described attack vector allows for significant amplification (up to 350x) of DoS traffic by exploiting HTTP/3 to HTTP/1.1 translation in CDNs, leading to high impact on availability and reasonable exploitability. A score in the High range is appropriate.

Defender Context

Defenders need to be aware of these CDN Tsunami attacks, which leverage a common HTTP protocol translation mechanism for DoS amplification. It highlights the importance of robust DoS mitigation strategies for origin servers, even when protected by CDNs, and to monitor traffic patterns for unusual amplification.

Read Full Story →