HTTP/3
Dr. Eng. Samer Khanji
HTTP/3 maps HTTP semantics onto the QUIC transport and is now a completed Internet standard. The design reduces handshake delay, removes TCP-level head-of-line blocking, and encrypts transport headers by default. Those same properties change the attack surface. This article reviews the architecture and features of HTTP/3, compares the protocol with HTTP/1.1 and HTTP/2 using published measurements, and organizes documented weaknesses into a compact taxonomy covering handshake resource exhaustion, 0-RTT replay, connection migration, QPACK state, privacy leakage, and gateway desynchronization. A recurring gap is identified: RFC 9000 limits unvalidated response volume to three times the received datagram size, which bounds byte amplification but does not bound the cryptographic CPU work spent on Initial and CRYPTO processing. The paper proposes REAP-H3 (Reputation-Enforced Adaptive Protection for HTTP/3), a server-side admission algorithm that combines address validation, a per-source crypto-cost budget, bounded incomplete-CRYPTO state, load-triggered puzzles, and a sliding Bloom filter for 0-RTT anti-replay. Discrete-event simulation, with cryptographic units calibrated to median OpenSSL timings of the TLS 1.3 primitives that RFC 9001 uses, shows that a byte-only baseline collapses under high-rate Initial floods, whereas REAP-H3 preserves high legitimate handshake success against both spoofed Initials and address-validated CRYPTO floods until the botnet becomes comparable in width to the server’s source budget. Sensitivity to C_max, ρ, U_max, and W is reported, together with an operational deployment profile.