H3Act: Automated Measuring Semantic Conversion Anomalies of HTTP/3-to-HTTP/1.1 Translation in CDNs
Qihang Peng, Siyuan Tian, Yongxin Qiu, Jinyang Huang, Yaru Yang, Xiang Li, Jia Zhang, Yiming Zhang, Haixin Duan, Yunsenxiao Lin, Shugen Chen, Liqun Yang
摘要
Content Delivery Networks (CDNs) are adopting HTTP/3 to enhance performance; however, they often need to convert it to HTTP/1.1 for compatibility. This conversion creates significant attack surfaces and may reintroduce confirmed or even patched vulnerabilities in HTTP/2 or HTTP/1. Unfortunately, existing tools struggle to adapt to the HTTP/3 environment and efficiently leverage accumulated attack knowledge. To overcome these challenges and systematically measure HTTP/3-to-HTTP/1.1 conversion anomalies within the black-box CDN environment, we present H3Act, a dual-agent, knowledge-driven fuzzing framework targeting HTTP/3-to-HTTP/1.1 semantic conversion anomalies. Our approach combines Large Language Models (LLMs) with Hybrid Retrieval-Augmented Generation (RAG) to automatically transform protocol specifications and historical threat intelligence into high-precision HTTP/3 test payloads, enabling regression testing of semantic translation risks. In a large-scale study of 9 commercial CDNs, including Cloudflare, Cloudfront, and Tencent CDN, we found a significant regression in protocol security, which means vulnerabilities in old protocols are reintroduced in HTTP/3. Our research identified 7 common attack vectors across various categories, including request smuggling, cache poisoning, and Denial-of-Service (DoS) amplification. Every CDN is vulnerable to at least one attack vector. We have responsibly disclosed these vulnerabilities and have received confirmations from some vendors. These findings highlight that the CDN ecosystem currently lacks the capacity to maintain security consistency checks while pursuing improvements in protocol performance.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper18
- Host of Troubles: Multiple Host Ambiguities in HTTP ImplementationsJianjun Chen, Jian Jiang, Hai-Xin Duan, Nicholas Weaver 等CCS 2016 · 被引用 49 次
- Forwarding-Loop Attacks in Content Delivery NetworksJianjun Chen, Xiaofeng Zheng, Hai-Xin Duan, Jinjin Liang 等NDSS 2016 · 被引用 44 次
- Your Cache Has Fallen: Cache-Poisoned Denial-of-Service AttackHoai Viet Nguyen, Luigi Lo Iacono, Hannes FederrathCCS 2019 · 被引用 41 次
- End-Users Get Maneuvered: Empirical Analysis of Redirection Hijacking in Content Delivery NetworksShuai Hao, Yubao Zhang, Haining Wang, Angelos StavrouUSENIX Security 2018 · 被引用 37 次
- T-Reqs: HTTP Request Smuggling with Differential FuzzingBahruz Jabiyev, Steven Sprecher, Kaan Onarlioglu, Engin KirdaCCS 2021 · 被引用 35 次
相关 Paper
- FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion AnomaliesBahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti 等USENIX Security 2022
- ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies and DoS Attacks with Grammar-based FuzzingLinkai Zheng, Xiang Li, Chuhan Wang, Run Guo 等NDSS 2024
- CDN Judo: Breaking the CDN DoS Protection with ItselfRun Guo, Weizhong Li, Baojun Liu, Shuang Hao 等NDSS 2020
- Internet's Invisible Enemy: Detecting and Measuring Web Cache Poisoning in the WildYuejia Liang, Jianjun Chen, Run Guo, Kaiwen Shen 等CCS 2024 · 被引用 1 次
- TLS 1.3 in Practice: How TLS 1.3 Contributes to the InternetHyunwoo Lee, Doowon Kim, Yonghwi KwonWWW 2021 · 被引用 47 次
