{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:56:12Z","timestamp":1783007772855,"version":"3.54.5"},"publisher-location":"Cham","reference-count":60,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031708893","type":"print"},{"value":"9783031708909","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-70890-9_1","type":"book-chapter","created":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T09:24:24Z","timestamp":1725528264000},"page":"3-23","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["PRETT2: Discovering HTTP\/2 DoS Vulnerabilities via\u00a0Protocol Reverse Engineering"],"prefix":"10.1007","author":[{"given":"Choongin","family":"Lee","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Isa","family":"Jafarov","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sven","family":"Dietrich","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Heejo","family":"Lee","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,9,6]]},"reference":[{"key":"1_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.jnca.2017.04.015","volume":"91","author":"E Adi","year":"2017","unstructured":"Adi, E., Baig, Z., Hingston, P.: Stealthy Denial of Service (DoS) attack modelling and detection for HTTP\/2 services. J. Netw. Comput. Appl. 91, 1\u201313 (2017)","journal-title":"J. Netw. Comput. Appl."},{"key":"1_CR2","doi-asserted-by":"crossref","unstructured":"Adi, E., Baig, Z., Lam, C.P., Hingston, P.: Low-rate denial-of-service attacks against HTTP\/2 services. In: 5th IEEE International Conference on IT Convergence and Security (ICITCS), pp.\u00a01\u20135 (2015)","DOI":"10.1109\/ICITCS.2015.7292994"},{"key":"1_CR3","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1007\/s10586-015-0528-7","volume":"19","author":"E Adi","year":"2016","unstructured":"Adi, E., Baig, Z.A., Hingston, P., Lam, C.P.: Distributed denial-of-service attacks against HTTP\/2 services. Clust. Comput. 19, 79\u201386 (2016)","journal-title":"Clust. Comput."},{"key":"1_CR4","doi-asserted-by":"crossref","unstructured":"Antunes, J., Neves, N., Verissimo, P.: Reverse engineering of protocols from network traces. In: 18th Working Conference on Reverse Engineering, pp. 169\u2013178. IEEE (2011)","DOI":"10.1109\/WCRE.2011.28"},{"key":"1_CR5","unstructured":"Apache Software Foundation: Apache HTTP Server. https:\/\/httpd.apache.org\/"},{"key":"1_CR6","unstructured":"Athapathu, R.: HTTP\/2 Flow Control (2019). https:\/\/medium.com\/coderscorner\/http-2-flow-control-77e54f7fd518"},{"key":"1_CR7","unstructured":"Ba, J., B\u00f6hme, M., Mirzamomen, Z., Roychoudhury, A.: Stateful Greybox Fuzzing. In: 31st USENIX Security Symposium, pp. 3255\u20133272 (2022)"},{"key":"1_CR8","doi-asserted-by":"crossref","unstructured":"Beckett, D., Sezer, S.: HTTP\/2 Cannon: experimental analysis on HTTP\/1 and HTTP\/2 request flood DDoS attacks. In: Seventh IEEE International Conference on Emerging Security Technologies (EST), pp. 108\u2013113 (2017)","DOI":"10.1109\/EST.2017.8090408"},{"key":"1_CR9","unstructured":"Belson, D., Pardue, L.: Examining HTTP\/3 usage one year on. Cloudflare (2023). https:\/\/blog.cloudflare.com\/http3-usage-one-year-on\/"},{"key":"1_CR10","doi-asserted-by":"crossref","unstructured":"Berners-Lee, T., Fielding, R., Frystyk, H.: RFC1945: Hypertext transfer protocol\u2013http\/1.0 (1996)","DOI":"10.17487\/rfc1945"},{"key":"1_CR11","doi-asserted-by":"crossref","unstructured":"Caballero, J., Yin, H., Liang, Z., Song, D.: Polyglot: automatic extraction of protocol message format using dynamic binary analysis. In: 14th ACM Conference on Computer and Communications Security, pp. 317\u2013329 (2007)","DOI":"10.1145\/1315245.1315286"},{"key":"1_CR12","doi-asserted-by":"publisher","first-page":"300","DOI":"10.1504\/IJTMCC.2013.056440","volume":"1","author":"E Cambiaso","year":"2013","unstructured":"Cambiaso, E., Papaleo, G., Chiola, G., Aiello, M.: Slow DoS attacks: definition and categorisation. Int. J. Trust Manage. Comput. Commun. 1, 300\u2013319 (2013)","journal-title":"Int. J. Trust Manage. Comput. Commun."},{"key":"1_CR13","doi-asserted-by":"crossref","unstructured":"Cho, C.Y., Babi\u00a0\u0107, D., Shin, E.C.R., Song, D.: Inference and analysis of formal models of botnet command and control protocols. In: 17th ACM conference on Computer and Communications Security, pp. 426\u2013439 (2010)","DOI":"10.1145\/1866307.1866355"},{"key":"1_CR14","doi-asserted-by":"crossref","unstructured":"Comparetti, P.M., Wondracek, G., Kruegel, C., Kirda, E.: Prospex: Protocol specification extraction. In: 30th IEEE Symposium on Security and Privacy, pp. 110\u2013125 (2009)","DOI":"10.1109\/SP.2009.14"},{"key":"1_CR15","doi-asserted-by":"crossref","unstructured":"Corbel, R., Stephan, E., Omnes, N.: HTTP\/1.1 pipelining vs HTTP2 in-the-clear: performance comparison. In: 13th IEEE International Conference on New Technologies for Distributed Systems (NOTERE), pp.\u00a01\u20136 (2016)","DOI":"10.1109\/NOTERE.2016.7745823"},{"key":"1_CR16","unstructured":"CVE-2016-1546. National Vulnerability Database (Jul 2016). http:\/\/nvd.nist.gov\/nvd.cfm?cvename=CVE-2016-1546"},{"key":"1_CR17","unstructured":"De\u00a0Ruiter, J., Poll, E.: Protocol state fuzzing of TLS implementations. In: 24th USENIX Security Symposium, pp. 193\u2013206 (2015)"},{"key":"1_CR18","unstructured":"DeNA: H2O Web Server. https:\/\/h2o.examp1e.net\/"},{"key":"1_CR19","unstructured":"F5: Nginx. https:\/\/nginx.org\/"},{"key":"1_CR20","doi-asserted-by":"crossref","unstructured":"Fielding, R., et\u00a0al.: Hypertext transfer protocol\u2013http\/1.1. Tech. rep. (1999)","DOI":"10.17487\/rfc2616"},{"key":"1_CR21","doi-asserted-by":"crossref","unstructured":"Gascon, H., Wressnegger, C., Yamaguchi, F., Arp, D., Rieck, K.: Pulsar: stateful black-box fuzzing of proprietary network protocols. In: International Conference on Security and Privacy in Communication Systems, pp. 330\u2013347 (2015)","DOI":"10.1007\/978-3-319-28865-9_18"},{"key":"1_CR22","doi-asserted-by":"crossref","unstructured":"Guo, R., et\u00a0al.: CDN Judo: breaking the CDN DoS protection with itself. In: Network and Distributed System Security Symposium (2020)","DOI":"10.14722\/ndss.2020.24411"},{"key":"1_CR23","unstructured":"IETF HTTP Working Group: List of known HTTP\/2 implementations (2020). https:\/\/github.com\/httpwg\/http2-spec\/wiki\/Implementations"},{"key":"1_CR24","unstructured":"Imperva: HTTP\/2: In-depth analysis of the top four flaws of the next generation web protocol (2017). https:\/\/www.imperva.com\/docs\/Imperva_HII_HTTP2.pdf"},{"key":"1_CR25","doi-asserted-by":"crossref","unstructured":"Jiang, M., Luo, X., Miu, T., Hu, S., Rao, W.: Are HTTP\/2 servers ready yet? In: 37th IEEE International Conference on Distributed Computing Systems (ICDCS), pp. 1661\u20131671 (2017)","DOI":"10.1109\/ICDCS.2017.279"},{"key":"1_CR26","unstructured":"Kaloper-Mer\u0161injak, D., Mehnert, H., Madhavapeddy, A., Sewell, P.: Not-Quite-So-Broken TLS: Lessons in re-engineering a security protocol specification and implementation. In: 24th USENIX Security Symposium, pp. 223\u2013238 (2015)"},{"key":"1_CR27","doi-asserted-by":"crossref","unstructured":"LaRoche, P., Burrows, A., Zincir-Heywood, A.N.: How far an evolutionary approach can go for protocol state analysis and discovery. In: IEEE Congress on Evolutionary Computation, pp. 3228\u20133235 (2013)","DOI":"10.1109\/CEC.2013.6557965"},{"key":"1_CR28","doi-asserted-by":"crossref","unstructured":"Lee, C., Bae, J., Lee, H.: PRETT: protocol reverse engineering using binary tokens and network traces. In: IFIP International Conference on ICT Systems Security and Privacy Protection, pp. 141\u2013155 (2018)","DOI":"10.1007\/978-3-319-99828-2_11"},{"key":"1_CR29","doi-asserted-by":"crossref","unstructured":"Ling, X., Wu, C., Ji, S., Han, M.: $$H_2$$ DoS: an application-layer DoS attack towards HTTP\/2 protocol. In: International Conference on Security and Privacy in Communication Systems, pp. 550\u2013570 (2017)","DOI":"10.1007\/978-3-319-78813-5_28"},{"key":"1_CR30","unstructured":"Mirkovi\u0107, J., Dietrich, S., Dittrich, D., Reiher, P.: Internet denial of service: attack and defense mechanisms. Prentice Hall PTR (2004)"},{"key":"1_CR31","unstructured":"Mozilla Foundation: Mozilla Firefox. https:\/\/www.mozilla.org\/firefox\/"},{"key":"1_CR32","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2840724","volume":"48","author":"J Narayan","year":"2015","unstructured":"Narayan, J., Shukla, S.K., Clancy, T.C.: A survey of automatic protocol reverse engineering tools. ACM Comput. Surv. (CSUR) 48, 1\u201326 (2015)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"1_CR33","doi-asserted-by":"publisher","first-page":"1775","DOI":"10.1109\/ACCESS.2021.3138768","volume":"10","author":"CK Nkuba","year":"2021","unstructured":"Nkuba, C.K., Kim, S., Dietrich, S., Lee, H.: Riding the Iot wave with vfuzz: discovering security flaws in smart homes. IEEE Access 10, 1775\u20131789 (2021)","journal-title":"IEEE Access"},{"key":"1_CR34","unstructured":"Opera Software: Opera Browser. https:\/\/www.opera.com\/"},{"key":"1_CR35","doi-asserted-by":"crossref","unstructured":"Park, H., Nkuba, C.K., Woo, S., Lee, H.: L2fuzz: discovering bluetooth l2cap vulnerabilities using stateful fuzz testing. In: 52nd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 343\u2013354 (2022)","DOI":"10.1109\/DSN53405.2022.00043"},{"key":"1_CR36","doi-asserted-by":"crossref","unstructured":"Pham, V.T., B\u00f6hme, M., Roychoudhury, A.: AFLNET: A greybox fuzzer for network protocols. In: IEEE 13th International Conference on Software Testing, Validation and Verification (ICST), pp. 460\u2013465 (2020)","DOI":"10.1109\/ICST46399.2020.00062"},{"key":"1_CR37","doi-asserted-by":"crossref","unstructured":"Poll, E., De\u00a0Ruiter, J., Schubert, A.: Protocol state machines and session languages: specification, implementation, and security flaws. In: IEEE Security and Privacy Workshops. pp. 125\u2013133 (2015)","DOI":"10.1109\/SPW.2015.32"},{"key":"1_CR38","doi-asserted-by":"publisher","first-page":"1790","DOI":"10.1109\/TIFS.2019.2950121","volume":"15","author":"A Praseed","year":"2019","unstructured":"Praseed, A., Thilagam, P.S.: Multiplexed asymmetric attacks: Next-generation DDoS on HTTP\/2 servers. IEEE Trans. Inf. Forensics Secur. 15, 1790\u20131800 (2019)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"1_CR39","doi-asserted-by":"crossref","unstructured":"Shevertalov, M., Mancoridis, S.: A reverse engineering tool for extracting protocols of networked applications. In: 14th Working Conference on Reverse Engineering (WCRE), pp. 229\u2013238 (2007)","DOI":"10.1109\/WCRE.2007.6"},{"key":"1_CR40","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1145\/2656877.2656896","volume":"44","author":"D Stenberg","year":"2014","unstructured":"Stenberg, D.: HTTP2 Explained. ACM SIGCOMM Comput. Commun. Rev. 44, 120\u2013128 (2014)","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"1_CR41","unstructured":"Stuart\u00a0Larsen, J.V.: Attacking HTTP\/2 Implementations. Yahoo pentest team (2015). https:\/\/www.slideshare.net\/JohnVillamil\/attacking-http2-implementations-1"},{"key":"1_CR42","unstructured":"The Chromium Projects: Chromium. https:\/\/www.chromium.org\/"},{"key":"1_CR43","unstructured":"The Chromium Projects: SPDY: An experimental protocol for a faster web (2009). https:\/\/www.chromium.org\/spdy\/"},{"key":"1_CR44","unstructured":"Thomson, M.: The SSLKEYLOGFILE Format for TLS. Tech. rep., Internet Engineering Task Force (Apr 2024). https:\/\/datatracker.ietf.org\/doc\/draft-ietf-tls-keylogfile\/01\/"},{"key":"1_CR45","doi-asserted-by":"publisher","unstructured":"Thomson, M., Benfield, C.: HTTP\/2. RFC 9113 (Jun 2022). https:\/\/doi.org\/10.17487\/RFC9113, https:\/\/www.rfc-editor.org\/info\/rfc9113","DOI":"10.17487\/RFC9113"},{"key":"1_CR46","doi-asserted-by":"crossref","unstructured":"Trifil\u00f2, A., Burschka, S., Biersack, E.: Traffic to protocol reverse engineering. In: IEEE Symposium on Computational Intelligence for Security and Defense Applications, pp.\u00a01\u20138 (2009)","DOI":"10.1109\/CISDA.2009.5356565"},{"key":"1_CR47","doi-asserted-by":"crossref","unstructured":"Tripathi, N.: Delays have Dangerous Ends: Slow HTTP\/2 DoS attacks into the Wild and their Real-Time Detection using Event Sequence Analysis. IEEE Transactions on Dependable and Secure Computing (2023)","DOI":"10.1109\/COMSNETS53615.2022.9668408"},{"key":"1_CR48","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1016\/j.cose.2017.09.009","volume":"72","author":"N Tripathi","year":"2018","unstructured":"Tripathi, N., Hubballi, N.: Slow rate denial of service attacks against HTTP\/2 and detection. Comput. Security 72, 255\u2013272 (2018)","journal-title":"Comput. Security"},{"key":"1_CR49","doi-asserted-by":"crossref","unstructured":"Tripathi, N., Shaji, A.K.: Defer no time, delays have dangerous ends: slow HTTP\/2 DoS attacks into the wild. In: 14th IEEE International Conference on COMmunication Systems and NETworkS (COMSNETS), pp. 194\u2013198 (2022)","DOI":"10.1109\/COMSNETS53615.2022.9668408"},{"key":"1_CR50","doi-asserted-by":"crossref","unstructured":"Beckett, D., Sezer, S.: HTTP\/2 Tsunami: Investigating HTTP\/2 proxy amplification DDoS attacks. In: Seventh IEEE International Conference on Emerging Security Technologies (EST). pp. 128\u2013133 (2017)","DOI":"10.1109\/EST.2017.8090411"},{"key":"1_CR51","unstructured":"W3Schools: The most popular browsers (Jan 2024). https:\/\/www.w3schools.com\/browsers"},{"key":"1_CR52","unstructured":"W3Techs: Web servers market position report (Jan 2024). https:\/\/w3techs.com\/technologies\/market\/web_server"},{"key":"1_CR53","doi-asserted-by":"crossref","unstructured":"Wang, Y., Zhang, Z., Yao, D.D., Qu, B., Guo, L.: Inferring protocol state machine from network traces: a probabilistic approach. In: International Conference on Applied Cryptography and Network Security, pp. 1\u201318 (2011)","DOI":"10.1007\/978-3-642-21554-4_1"},{"key":"1_CR54","doi-asserted-by":"crossref","unstructured":"Wijnants, M., Marx, R., Quax, P., Lamotte, W.: HTTP\/2 prioritization and its impact on web performance. In: Proceedings of the 2018 World Wide Web Conference, pp. 1755\u20131764 (2018)","DOI":"10.1145\/3178876.3186181"},{"key":"1_CR55","unstructured":"Wondracek, G., Comparetti, P.M., Kruegel, C., Kirda, E.: Automatic network protocol analysis. In: Network and Distributed System Security Symposium (2008)"},{"key":"1_CR56","doi-asserted-by":"crossref","unstructured":"Xiao, M.M., Yu, S.Z., Wang, Y.: Automatic network protocol automaton extraction. In: Third International Conference on Network and System Security, pp. 336\u2013343 (2009)","DOI":"10.1109\/NSS.2009.71"},{"key":"1_CR57","unstructured":"Yahia, M.B., Le\u00a0Louedec, Y., Simon, G., Nuaymi, L.: HTTP\/2-Based streaming solutions for tiled omnidirectional videos. In: IEEE International Symposium on Multimedia (ISM), pp. 89\u201396 (2018)"},{"key":"1_CR58","doi-asserted-by":"crossref","unstructured":"Yahia, M.B., Louedec, Y.L., Simon, G., Nuaymi, L., Corbillon, X.: HTTP\/2-based Frame discarding for low-latency adaptive video streaming. ACM Trans. Multimedia Comput., Commun. Appl. (TOMM) 15, 1\u201323 (2019)","DOI":"10.1145\/3280854"},{"key":"1_CR59","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Shi, Y.: A slow rate denial-of-service attack against HTTP\/2. In: IEEE 4th International Conference on Computer and Communications (ICCC), pp. 1388\u20131391 (2018)","DOI":"10.1109\/CompComm.2018.8780763"},{"key":"1_CR60","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Wen, Q.Y., Tang, W.: Mining Protocol State Machines by Interactive Grammar Inference. In: Third IEEE International Conference on Digital Manufacturing and Automation, pp. 524\u2013527 (2012)","DOI":"10.1109\/ICDMA.2012.125"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-70890-9_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T09:24:57Z","timestamp":1725528297000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-70890-9_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031708893","9783031708909"],"references-count":60,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-70890-9_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"6 September 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Bydgoszcz","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Poland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 September 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2024.org","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}