FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies
Bahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti, Kaan Onarlioglu, Engin Kirda
摘要
HTTP/2 adoption is rapidly climbing. However, in practice, Internet communications still rarely happen over end-to-end HTTP/2 channels. This is due to Content Delivery Networks and other reverse proxies, ubiquitous and necessary components of the Internet ecosystem, which only support HTTP/2 on the client's end, but not the forward connection to the origin server. Instead, proxy technologies predominantly rely on HTTP/2-to-HTTP/1 protocol conversion between the two legs of the connection. We present the first systematic exploration of HTTP/2-to-HTTP/1 protocol conversion anomalies and their security implications. We develop a novel grammar-based fuzzer for HTTP/2, experiment with 12 popular reverse proxy technologies & CDNs through HTTP/2 frame sequence and content manipulation, and discover a plethora of novel web application attack vectors that lead to Request Blackholing, Denialof-Service, Query-of-Death, and Request Smuggling attacks. DATA: Carries a request or a response body. HEADERS: Carries header fields of a request or a response. PRIORITY: Specifies the priority of a stream and its dependency on another stream. RST_STREAM: Terminates the stream. SETTINGS: Conveys information about preferences and constraints of the sender. PUSH_PROMISE: Notifies the peer endpoint about streams it intends to initiate in the future. PING: Measures round-trip time and checks if an idle connection is still functional. GOAWAY: Shuts down a connection. WINDOW_UPDATE: Implements flow control. CONTINUATION: Continues a sequence of header fields. HTTP/2-to-HTTP/1 Conversion HTTP/2 is the most widely used HTTP version by clients today. A 7M-site measurement using the Chrome browser, done by the HTTP Archive in 2020, showed that 64% of requests use HTTP/2 [10].
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Lifting Network Protocol Implementation to Precise Format Specification with Security ApplicationsQingkai Shi, Junyang Shao, Yapeng Ye, Mingwei Zheng 等CCS 2023 · 被引用 15 次
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan 等USENIX Security 2024 · 被引用 13 次
- H3Act: Automated Measuring Semantic Conversion Anomalies of HTTP/3-to-HTTP/1.1 Translation in CDNsQihang Peng, Siyuan Tian, Yongxin Qiu, Jinyang Huang 等USENIX Security 2026
- NCFuzz: Configuration-Guided Network Service FuzzingXuesong Bai, Hengkai Ye, Shenghan Zheng, Fenglu Zhang 等ISSTA 2026
- Untangle: Multi-Layer Web Server FingerprintingCem Topcuoglu, Kaan Onarlioglu, Bahruz Jabiyev, Engin KirdaNDSS 2024
它引用的顶会 Paper7
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig 等NDSS 2019 · 被引用 291 次
- Your Cache Has Fallen: Cache-Poisoned Denial-of-Service AttackHoai Viet Nguyen, Luigi Lo Iacono, Hannes FederrathCCS 2019 · 被引用 41 次
- T-Reqs: HTTP Request Smuggling with Differential FuzzingBahruz Jabiyev, Steven Sprecher, Kaan Onarlioglu, Engin KirdaCCS 2021 · 被引用 35 次
- Web Cache Deception Escalates!Seyed Ali Mirheidari, Matteo Golinelli, Kaan Onarlioglu, Engin Kirda 等USENIX Security 2022
- Cached and Confused: Web Cache Deception in the WildSeyed Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu, Bruno Crispo 等USENIX Security 2020
相关 Paper
- SPCA: Stream Parser Confusion Attack for Web Application Firewall Evasion in HTTP/2Kyungrok Choi, Woonghee Lee, Junbeom HurWWW 2026
- CDN Judo: Breaking the CDN DoS Protection with ItselfRun Guo, Weizhong Li, Baojun Liu, Shuang Hao 等NDSS 2020
- MadeYouReset: Exploiting HTTP/2 Server-Side Resets for Large-Scale DoSGal Bar Nahum, Anat Bremler Barr, Yaniv HarelS&P 2026
- ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies and DoS Attacks with Grammar-based FuzzingLinkai Zheng, Xiang Li, Chuhan Wang, Run Guo 等NDSS 2024
- A Large-Scale Measurement Study of the PROXY Protocol and its Security ImplicationsStijn Pletinckx, Christopher Kruegel, Giovanni VignaNDSS 2025
