Skip to content

Proposal: Support HTTP2 fingerprint #1071

Closed
@deancn

Description

Is your feature request related to a problem? Please describe.
In recent years, cyber security is facing more and more issues, as a gateway component, BFE should consider and improve the security part.
We can see BFE already integrated with ja3(salesforce), it's very good. But ja3 can be impersonated easier and easier

We found a good solution - http2fingerprint(akamai) this year, and i have already used it. so I propose to implement it in BFE.
Demo: https://privacycheck.sec.lrz.de/passive/fp_h2/fp_http2.html#fpDemoHttp2

Describe the solution you'd like

Describe alternatives you've considered

Additional context
Reference Paper:
https://www.blackhat.com/docs/eu-17/materials/eu-17-Shuster-Passive-Fingerprinting-Of-HTTP2-Clients-wp.pdf

A simple implement by @xqbumu:
#1072

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions