QUICforge: Client-side Request Forgery in QUIC
Konrad Yuri Gbur, Florian Tschorsch
Abstract
—The QUIC protocol is gaining more and more traction through its recent standardization and the rising interest by various big tech companies, developing new implementations. QUIC promises to make security and privacy a first-class citizen; yet, challenging these claims is of utmost importance. To this end, this paper provides an initial analysis of client-side request forgery attacks that directly emerge from the QUIC protocol design and not from common vulnerabilities. In particular, we investigate three request forgery attack modalities with respect to their capabilities to be used for protocol impersonation and traffic amplification. We analyze the controllable attack space of the respective protocol messages and demonstrate that one of the attack modalities can indeed be utilized to impersonate other UDP-based protocols, e.g., DNS requests. Furthermore, we identify traffic amplification vectors. Although the QUIC protocol specification states anti-amplification limits, our evaluation of 13 QUIC server implementations shows that in some cases these mitigations are missing or insufficiently implemented. Lastly, we propose mitigation approaches for protocol impersonation and discuss ambiguities in the specification.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Detecting Tunneled Flooding Traffic via Deep Semantic Analysis of Packet Length PatternsChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2024 · 13 citations
- Identifying Logical Vulnerabilities in QUIC ImplementationsKaihua Wang, Jianjun Chen, Pinji Chen, Jianwei Zhuge et al.NDSS 2026 · 1 citation
- TurboRetry: Mitigating Large-Scale QUIC Handshake Floods with Off-the-Shelf DPU OffloadingJiahao Wu, Heng Pan, Kai Lv, Zhenyu Li et al.CCS 2026
- Breaking the Boundaries: Analyzing QUIC Frame-Packet Interactions With QUIC-AttackerNurullah Erinola, Marcel Maehren, Marcus Brinkmann, Jörg SchwenkUSENIX Security 2026
- SoK: Decoding the Enigma of Encrypted Network Traffic ClassifiersNimesha Wickramasinghe, Arash Shaghaghi, Gene Tsudik, Sanjay K. JhaS&P 2025
Builds on1
Related papers
- Dissecting Performance of Production QUICAlexander Yu, Theophilus A. BensonWWW 2021 · 59 citations
- A Security Model and Fully Verified Implementation for the IETF QUIC Record LayerAntoine Delignat-Lavaud, Cédric Fournet, Bryan Parno, Jonathan Protzenko et al.S&P 2021 · 30 citations
- QUIC is not Quick Enough over Fast InternetXumiao Zhang, Shuowei Jin, Yi He, Ahmad Hassan et al.WWW 2024 · 32 citations
- QCSD: A QUIC Client-Side Website-Fingerprinting Defence FrameworkJean-Pierre Smith, Luca Dolfi, Prateek Mittal, Adrian PerrigUSENIX Security 2022
- Loopy Hell(ow): Infinite Traffic Loops at the Application LayerYepeng Pan, Anna Ascheman, Christian RossowUSENIX Security 2024 · 4 citations
