A new DDoS (distributed denial of service) technique named 'HTTP/2 Rapid Reset' has been actively exploited as a zero-day since August, breaking all previous records in magnitude. News of the zero-day technique comes as a coordinated announcement today between Amazon Web Services, Cloudflare, and Google, who report mitigating attacks reaching 155 million requests per second (Amazon), 201 million rps (Cloudflare), and a record-breaking 398 million rps (Google). Google says they were able to mitigate these new attacks by adding further capacity on the edge of their network. Cloudflare comments that the size of the attack it mitigated is three times bigger than its previous record, from February 2023 (71 million rps), and it's alarming that this was achieved using a relatively small botnet comprising 20,000 machines. Since late August, Cloudflare has detected and mitigated over a thousand 'HTTP/2 Rapid Reset' DDoS attacks that surpassed 10 million rps, with 184 breaking the previous 71 million rps record. Cloudflare is confident that as further threat actors employ more expansive botnets along with this new attack method, HTTP/2 Rapid Reset attacks will continue to break even greater records. "There are botnets today that are made up of hundreds of thousands or millions of machines," comments Cloudflare. "Given that the entire web typically sees only between 1–3 billion requests per second, it's not inconceivable that using this method could focus an entire web's worth of reque...
New 'HTTP/2 Rapid Reset' zero-day attack breaks DDoS records
BleepingComputer
·Published Oct 10, 2023
·Updated
Affected Software
2 affected components
IETF HTTP/2
Various HTTP/2 proxy/load-balancer implementations
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new DDoS attack technique called 'HTTP/2 Rapid Reset' that exploits a zero-day vulnerability.
2
What security implications are discussed?
The article highlights the severe risk posed by the 'HTTP/2 Rapid Reset' attack, which breaks previous DDoS attack records in magnitude.
3
What products or software are affected?
The attack affects systems utilizing the HTTP/2 protocol, although specific affected software is not identified.
4
When was this zero-day attack first exploited?
The 'HTTP/2 Rapid Reset' zero-day attack has been actively exploited since August.
5
How does the 'HTTP/2 Rapid Reset' technique work?
The article provides an overview of the technique but does not go into specific technical details.