USENIX Security2026Top-tier venue
Breaking the Boundaries: Analyzing QUIC Frame-Packet Interactions With QUIC-Attacker
Nurullah Erinola, Marcel Maehren, Marcus Brinkmann, Jörg Schwenk
Abstract
QUIC is a new network protocol based on UDP that replaces TCP and TLS with an integrated protocol. It provides multiplexing of streams over a single encrypted and authenticated connection. The QUIC standard allows many different combinations of UDP datagrams, and QUIC packets, frames, and streams to transport the same information. This implies that testing the receiving side of QUIC is difficult.
We develop probes to explore how different QUIC server implementations handle the coalescence and fragmentation of payloads, covering both valid and invalid combinations of datagrams, packets, and frames. Already at this basic level, we observe significant differences between implementations, some of which pointing towards exploitable vulnerabilities. Previous QUIC research tools were not designed to implement such probes. To address this limitation, we present QUIC-Attacker, a testing framework that allows maximum freedom on the sending side of QUIC.
We present our results on these probes when applied to 15 QUIC server libraries, uncovering eight DoS vulnerabilities caused by unhandled exceptions and exploitable injection vulnerabilities in Kwik and Alibaba's XQUIC.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 170e23f1-dc15-4b86-8649-64586a7d904aBuilds on4
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 136 citations
- Prognosis: closed-box analysis of network protocol implementationsTiago Ferreira, Harrison Brewton, Loris D'Antoni, Alexandra SilvaSIGCOMM 2021 · 34 citations
- QUICforge: Client-side Request Forgery in QUICKonrad Yuri Gbur, Florian TschorschNDSS 2023
- Opossum Attack: Application Layer Desynchronization using Opportunistic TLSRobert Merget, Nurullah Erinola, Marcel Maehren, Lukas Knittel et al.USENIX Security 2026
Related papers
- Identifying Logical Vulnerabilities in QUIC ImplementationsKaihua Wang, Jianjun Chen, Pinji Chen, Jianwei Zhuge et al.NDSS 2026 · 1 citation
- Dissecting Performance of Production QUICAlexander Yu, Theophilus A. BensonWWW 2021 · 59 citations
- A Security Model and Fully Verified Implementation for the IETF QUIC Record LayerAntoine Delignat-Lavaud, Cédric Fournet, Bryan Parno, Jonathan Protzenko et al.S&P 2021 · 30 citations
- Analysis of DTLS Implementations Using Protocol State FuzzingPaul Fiterau-Brostean, Bengt Jonsson, Robert Merget, Joeri de Ruiter et al.USENIX Security 2020
- QUIC is not Quick Enough over Fast InternetXumiao Zhang, Shuowei Jin, Yi He, Ahmad Hassan et al.WWW 2024 · 32 citations
