CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Summary
Cybersecurity researchers have discovered two denial-of-service (DoS) attacks, dubbed "CDN Tsunami," that exploit the translation of HTTP/3 to HTTP/1.1 traffic by major content delivery networks (CDNs). These attacks can amplify low-bandwidth requests by up to 350 times against origin servers.
IFF Assessment
This article details new denial-of-service attack techniques that can significantly impact the availability of online services, posing a direct threat to defenders.
Severity
The described attack vector allows for significant amplification (up to 350x) of DoS traffic by exploiting HTTP/3 to HTTP/1.1 translation in CDNs, leading to high impact on availability and reasonable exploitability. A score in the High range is appropriate.
Defender Context
Defenders need to be aware of these CDN Tsunami attacks, which leverage a common HTTP protocol translation mechanism for DoS amplification. It highlights the importance of robust DoS mitigation strategies for origin servers, even when protected by CDNs, and to monitor traffic patterns for unusual amplification.