USENIX Security2022Top-tier venue
FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies
Bahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti, Kaan Onarlioglu, Engin Kirda
Abstract
HTTP/2 adoption is rapidly climbing. However, in practice, Internet communications still rarely happen over end-to-end HTTP/2 channels. This is due to Content Delivery Networks and other reverse proxies, ubiquitous and necessary components of the Internet ecosystem, which only support HTTP/2 on the client's end, but not the forward connection to the origin server. Instead, proxy technologies predominantly rely on HTTP/2-to-HTTP/1 protocol conversion between the two legs of the connection. We present the first systematic exploration of HTTP/2-to-HTTP/1 protocol conversion anomalies and their security implications. We develop a novel grammar-based fuzzer for HTTP/2, experiment with 12 popular reverse proxy technologies & CDNs through HTTP/2 frame sequence and content manipulation, and discover a plethora of novel web application attack vectors that lead to Request Blackholing, Denialof-Service, Query-of-Death, and Request Smuggling attacks. DATA: Carries a request or a response body. HEADERS: Carries header fields of a request or a response. PRIORITY: Specifies the priority of a stream and its dependency on another stream. RST_STREAM: Terminates the stream. SETTINGS: Conveys information about preferences and constraints of the sender. PUSH_PROMISE: Notifies the peer endpoint about streams it intends to initiate in the future. PING: Measures round-trip time and checks if an idle connection is still functional. GOAWAY: Shuts down a connection. WINDOW_UPDATE: Implements flow control. CONTINUATION: Continues a sequence of header fields. HTTP/2-to-HTTP/1 Conversion HTTP/2 is the most widely used HTTP version by clients today. A 7M-site measurement using the Chrome browser, done by the HTTP Archive in 2020, showed that 64% of requests use HTTP/2 [10].
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 084a370c-001c-49eb-92be-2eb815d2a3f5Cited by top-tier papers6
- Lifting Network Protocol Implementation to Precise Format Specification with Security ApplicationsQingkai Shi, Junyang Shao, Yapeng Ye, Mingwei Zheng et al.CCS 2023 · 15 citations
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan et al.USENIX Security 2024 · 13 citations
- H3Act: Automated Measuring Semantic Conversion Anomalies of HTTP/3-to-HTTP/1.1 Translation in CDNsQihang Peng, Siyuan Tian, Yongxin Qiu, Jinyang Huang et al.USENIX Security 2026
- NCFuzz: Configuration-Guided Network Service FuzzingXuesong Bai, Hengkai Ye, Shenghan Zheng, Fenglu Zhang et al.ISSTA 2026
- Untangle: Multi-Layer Web Server FingerprintingCem Topcuoglu, Kaan Onarlioglu, Bahruz Jabiyev, Engin KirdaNDSS 2024
Builds on7
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
- Your Cache Has Fallen: Cache-Poisoned Denial-of-Service AttackHoai Viet Nguyen, Luigi Lo Iacono, Hannes FederrathCCS 2019 · 41 citations
- T-Reqs: HTTP Request Smuggling with Differential FuzzingBahruz Jabiyev, Steven Sprecher, Kaan Onarlioglu, Engin KirdaCCS 2021 · 35 citations
- Web Cache Deception Escalates!Seyed Ali Mirheidari, Matteo Golinelli, Kaan Onarlioglu, Engin Kirda et al.USENIX Security 2022
- Cached and Confused: Web Cache Deception in the WildSeyed Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu, Bruno Crispo et al.USENIX Security 2020
Related papers
- SPCA: Stream Parser Confusion Attack for Web Application Firewall Evasion in HTTP/2Kyungrok Choi, Woonghee Lee, Junbeom HurWWW 2026
- CDN Judo: Breaking the CDN DoS Protection with ItselfRun Guo, Weizhong Li, Baojun Liu, Shuang Hao et al.NDSS 2020
- MadeYouReset: Exploiting HTTP/2 Server-Side Resets for Large-Scale DoSGal Bar Nahum, Anat Bremler Barr, Yaniv HarelS&P 2026
- ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies and DoS Attacks with Grammar-based FuzzingLinkai Zheng, Xiang Li, Chuhan Wang, Run Guo et al.NDSS 2024
- A Large-Scale Measurement Study of the PROXY Protocol and its Security ImplicationsStijn Pletinckx, Christopher Kruegel, Giovanni VignaNDSS 2025
