Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →HTTP/2 Rapid Reset is the name for CVE-2023-44487, a denial-of-service flaw affecting HTTP/2 implementations. Attackers repeatedly opened HTTP/2 streams and canceled them with RST_STREAM frames, making servers do work for requests that were immediately abandoned. In 2023, Cloudflare and Google reported attacks peaking above 201 million and 398 million requests per second, respectively. Those were provider-observed Layer 7 rates—not a single, independently measured record of all DDoS traffic worldwide. For operators, the key question is whether an internet-facing service accepts HTTP/2 and, if so, whether its specific implementation has the vendor’s fix.
How the Rapid Reset attack works
HTTP/2 carries multiple concurrent streams over a connection. A client can cancel a stream with an RST_STREAM frame. In a Rapid Reset attack, a client rapidly creates streams and cancels them, repeatedly making the server process stream setup and cancellation. The mismatch between the attacker’s effort and the server’s work can consume resources and make a service unavailable.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Network Security, Firewalls, and VPNs | $66.62 | Buy on Amazon |
| 2 |
|
Network Security, Firewalls, and VPNs: . (Issa) | $59.07 | Buy on Amazon |
| 3 |
|
TP-Link ER605, Wired Gigabit VPN Router | $44.99 | Buy on Amazon |
| 4 |
|
Cybersecurity for Small Networks: A Guide for the Reasonably Paranoid | $33.56 | Buy on Amazon |
A request rate is not the same as network bandwidth or packet rate. The headline figures for these attacks measure HTTP requests per second at the application layer. NIST’s National Vulnerability Database rated CVE-2023-44487 CVSS 7.5 High in 2023, with an availability-impact vector.
What made the 2023 attacks record-breaking?
Cloudflare and Google reported separate attacks against their own networks. Their peaks are not competing measurements of one event, and the available figures do not establish a universal record across every network or type of DDoS traffic.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
| Reported figure | What it describes |
|---|---|
| Just above 201 million requests per second | Cloudflare’s reported peak in 2023—nearly three times its previous record. |
| Above 398 million requests per second | Google Cloud’s reported peak in 2023—7.5 times its previous record. Google said its edge infrastructure stopped the attack without an outage. |
| About 20,000 machines | Cloudflare’s estimate of the attack’s machine count in its 2023 technical analysis. |
| Roughly 1–3 billion requests per second | Cloudflare’s contextual estimate for the ordinary web’s request volume, not an independently measured global census. |
The figures show why the technique drew attention: a comparatively modest botnet, by Cloudflare’s estimate, could generate an exceptionally high rate of application-layer work. They should not be read as evidence that every HTTP/2 service experienced the same rate or impact.
Which services may be exposed?
The practical exposure test is whether an internet-reachable service accepts HTTP/2. Microsoft described the vulnerability as impacting any internet-exposed HTTP/2 endpoint. CERT-EU listed nginx, Apache, IIS, and other HTTP/2 products among affected classes. That does not mean every release of every product is vulnerable: impact and remediation depend on the implementation and vendor release.
Rank #2
- Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
- New Chapter on detailing network topologies
- The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
- Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
- Increased coverage on device implantation and configuration
Check the components that terminate or process HTTP/2 traffic, not only the application behind them. Depending on the deployment, this may include a web server, operating-system HTTP stack, application runtime, reverse proxy, load balancer, or managed edge service.
Is CVE-2023-44487 still a threat?
A service running a vulnerable, unpatched HTTP/2 implementation remains at risk if it is reachable by attackers. CISA reported exploitation in the wild from August through October 2023. That establishes historical exploitation; it does not, by itself, establish the current prevalence of attacks. The cited 2023 disclosures do not establish whether exploitation is occurring now.
Rank #3
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
The vulnerability’s age does not make patching optional: an exposed endpoint that has not received its vendor’s remedy may still be vulnerable. Conversely, the presence of HTTP/2 alone is not enough to conclude that a particular endpoint remains vulnerable; verify its implementation, version, and vendor guidance.
How to check and mitigate an HTTP/2 service
- Inventory internet-facing endpoints. Identify services that accept HTTP/2, including public web servers, proxies, load balancers, and application runtimes. Record which component terminates each connection.
- Identify the implementation and release. Check the vendor’s advisory for that specific component and compare the installed release with the vendor’s stated affected and fixed releases. Do not infer status from the product name alone.
- Apply the vendor security update. CISA’s October 10, 2023 advisory recommends patching HTTP/2 services when patches are available. Microsoft reported fixes for IIS/HTTP.sys, .NET Kestrel, and Windows in its October 10, 2023 updates. Use the relevant vendor’s current instructions for the exact product and release; the cited advisories do not provide one universal patch version for all implementations.
- Use vendor configuration guidance if a patch is not available. CISA recommends considering configuration changes and other mitigations described in the relevant advisories. The appropriate settings vary by implementation, so do not copy a configuration change intended for another server or runtime.
- Put an appropriate mitigation layer in front of public services. A managed DDoS mitigation service can provide an additional layer for web-facing workloads. Confirm that the service covers the HTTP/2 endpoint and the kind of Layer 7 request flood you need to address.
- Check that the change took effect. Verify the deployed component and release, confirm traffic is passing through the intended protection layer, and review available service and security logs for unusual request rates or mitigation activity.
How the main defenses differ
| Defense | What it addresses | Deployment and coverage considerations |
|---|---|---|
| Vendor security patch | Remediates the affected implementation according to the vendor’s release guidance. | Must be applied to each relevant HTTP/2 component. Check every implementation in the request path; a patched application does not establish that a separate proxy or server is patched. |
| Vendor configuration mitigation | Can reduce exposure or risk where the vendor recommends settings as a mitigation. | Depends on the product and its supported configuration. Follow the implementation-specific instructions; it is not a substitute for an available security update unless the vendor says so. |
| Managed edge or DDoS protection | Adds a layer intended to absorb or mitigate attacks before they reach web-facing infrastructure. | Requires routing the relevant traffic through the service and verifying coverage for the endpoint and Layer 7 flood. Cloudflare reported automated mitigation of the attacks; Google said Cloud Armor on global or regional Application Load Balancers mitigates attacks exploiting CVE-2023-44487; AWS reported additional mitigations in its infrastructure. |
These defenses address different points in the request path. Edge protection can help absorb an attack, but it does not update a vulnerable origin. Patching the origin addresses the implementation, but does not by itself provide the traffic capacity or operational visibility of a managed mitigation service.
Quick Recap
What the vendors and agencies reported
- CISA: Its October 10, 2023 advisory said the flaw had been exploited in the wild from August through October 2023 and recommended patches when available, alongside configuration changes and other mitigations.
- Microsoft: Its October 10, 2023 update coverage included IIS/HTTP.sys, .NET Kestrel, and Windows. Operators should use Microsoft’s product-specific guidance to determine the applicable update.
- Cloudflare: It reported a peak just above 201 million requests per second and described automated mitigation. Its technical analysis estimated about 20,000 machines and offered the ordinary-web request-rate comparison as context.
- Google Cloud: It reported a peak above 398 million requests per second and said its edge infrastructure stopped the attack without an outage. Google also identified Cloud Armor protection on global or regional Application Load Balancers as a mitigation.
- AWS: Its October 10, 2023 security bulletin described the rapid creation and cancellation of streams as a source of additional server load and denial-of-service risk. AWS reported additional infrastructure mitigations and directed self-hosted customers to vendor patches.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

