CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

Read full story on The Hacker News
Share
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
AI disclosure

Summary

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin server. The attacks, collectively named "CDN Tsunami," were evaluated against Alibaba, Baidu,

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.