ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › HTTP/2 control frames

Layer 7 · Protocol · http2_ping_flood / http2_window_update_flood

HTTP/2 Control Frame & Stream Churn Test

Streams continuous sequences of HTTP/2 PING frames, empty SETTINGS modifications, and 1-byte incremental WINDOW_UPDATE frames to validate HTTP/2 session loop CPU bounds and frame rate-limiting controls.

Layer L7 Protocol HTTP/2 Commands http2_ping_flood, http2_window_update_flood Access Self-service / Quote

On this page

  1. What control frame floods test
  2. HTTP/2 PING & SETTINGS flood
  3. HTTP/2 WINDOW_UPDATE stream churn
  4. Safe execution
  5. Reading the results
  6. Related simulations

What control frame floods test

HTTP/2 allows clients to send control frames (such as PING, SETTINGS, PRIORITY, and WINDOW_UPDATE) asynchronously outside of active request/response data streams. Because RFC 7540 / 9113 mandates immediate server acknowledgment for PING frames and state tracking for WINDOW_UPDATEs, an adversary can burn high server CPU without sending any real request payload or triggering standard URL rate limiters.

HTTP/2 PING & SETTINGS flood (http2_ping_flood)

Sends continuous 8-byte PING frames expecting immediate PING-ACK responses, accompanied by empty SETTINGS frames. This tests whether your web server or proxy enforces control-frame rate limits (e.g. NGINX http2_max_concurrent_pushes, Envoy max_consecutive_inbound_frames_with_empty_payload) and prevents event-loop starvation.

HTTP/2 WINDOW_UPDATE stream churn (http2_window_update_flood)

Generates high-frequency 1-byte increment WINDOW_UPDATE frames on active streams. This exercises the server's flow-control state tracking and locks to confirm that stream state mutation does not cause thread lock contention or algorithmic degradation.

Safe execution

All simulations run against your verified domain with real TLS handshakes and rate-governed frame streams. Live health probes verify service availability throughout the test.

Reading the results

Resilient: The server caps control frame throughput per session or issues GOAWAY (ENHANCE_YOUR_CALM) if limits are exceeded, keeping CPU usage minimal.

Under strain: Worker process CPU saturates at 100% processing control-frame event queues, degrading legitimate HTTP/2 request processing.

Related simulations

HTTP/2 Rapid Reset Tests stream reset cancellation budget limits. HTTP/2 CONTINUATION flood Tests header buffer bounding under endless CONTINUATION frames. HTTP/2 MadeYouReset Tests server-provoked resets under adversarial protocol violations.

Validate your HTTP/2 control frame rate limits safely.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA