New 'CDN Tsunami' Attack Method Could Massively Amplify Website Outages
Security researchers have disclosed two new denial-of-service (DoS) attack techniques, collectively called 'CDN Tsunami', that exploit how major content delivery networks (CDNs) handle modern web traffic. CDNs sit between websites and their visitors, helping speed up and protect sites. The research found that when these networks convert newer HTTP/3 traffic from clients into older HTTP/1.1 requests for the origin website, a small amount of attacker traffic can be blown up into a much larger flood hitting the actual website server.
According to the findings, this translation process can amplify a low-bandwidth request stream by as much as 350 times before it reaches the origin server. The attacks were evaluated against services from major providers including Alibaba and Baidu, suggesting the issue is not limited to a single vendor but may reflect a broader design pattern used across the CDN industry.
For small and medium businesses, this matters because many websites rely on CDNs to stay fast and available, often without knowing the technical details of how traffic is processed behind the scenes. If attackers can use a small amount of traffic to overwhelm a business's website or online store, it could mean costly downtime, lost sales, and frustrated customers, even if the business itself did nothing wrong.