Back to all lessons
Awareness Lessons
4 months ago

HTTP/2 Protocol Features Weaponized in Amplification DoS Attacks

The HTTP/2 Bomb Attack exploits legitimate bandwidth-optimization features built into the HTTP/2 protocol, turning them into amplification vectors capable of overwhelming servers with minimal attacker effort. Telecommunications and healthcare organizations are particularly at risk because they rely heavily on high-availability services where even brief outages can have life-safety or regulatory consequences. The root issue lies in insufficient validation and rate-limiting of protocol-level features that were never hardened against malicious abuse. This matters because critical infrastructure sectors often run legacy or unpatched HTTP/2 implementations that lack mitigations for protocol-layer attacks, making them soft targets for adversaries seeking maximum disruption with low resource investment.

Tactical Insight

Immediate Actions

  • Audit all internet-facing HTTP/2-enabled servers and apply vendor-released patches or mitigations for known amplification vulnerabilities immediately.
  • Implement request rate-limiting and connection throttling at the load balancer or WAF layer to restrict abuse of HTTP/2 protocol features.

Long-Term Improvements

  • Establish a continuous vulnerability management program that includes protocol-level threat intelligence, not just CVE-based patching cycles.
  • Maintain an up-to-date inventory of all public-facing services and their protocol configurations to enable rapid response to emerging exploits.
  • Evaluate HTTP/2 server configurations to disable or restrict features (e.g., header compression, stream multiplexing limits) that are not operationally required.

Detection Measures

  • Deploy anomaly-based DDoS detection tools capable of identifying protocol-layer amplification patterns distinct from volumetric flood attacks.
  • Configure logging and monitoring to alert on abnormal HTTP/2 stream counts, header sizes, or connection durations that may indicate bomb-style exploitation.