QUICforge: Client-side Request Forgery in QUIC
Konrad Yuri Gbur, Florian Tschorsch
摘要
—The QUIC protocol is gaining more and more traction through its recent standardization and the rising interest by various big tech companies, developing new implementations. QUIC promises to make security and privacy a first-class citizen; yet, challenging these claims is of utmost importance. To this end, this paper provides an initial analysis of client-side request forgery attacks that directly emerge from the QUIC protocol design and not from common vulnerabilities. In particular, we investigate three request forgery attack modalities with respect to their capabilities to be used for protocol impersonation and traffic amplification. We analyze the controllable attack space of the respective protocol messages and demonstrate that one of the attack modalities can indeed be utilized to impersonate other UDP-based protocols, e.g., DNS requests. Furthermore, we identify traffic amplification vectors. Although the QUIC protocol specification states anti-amplification limits, our evaluation of 13 QUIC server implementations shows that in some cases these mitigations are missing or insufficiently implemented. Lastly, we propose mitigation approaches for protocol impersonation and discuss ambiguities in the specification.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Detecting Tunneled Flooding Traffic via Deep Semantic Analysis of Packet Length PatternsChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2024 · 被引用 13 次
- Identifying Logical Vulnerabilities in QUIC ImplementationsKaihua Wang, Jianjun Chen, Pinji Chen, Jianwei Zhuge 等NDSS 2026 · 被引用 1 次
- TurboRetry: Mitigating Large-Scale QUIC Handshake Floods with Off-the-Shelf DPU OffloadingJiahao Wu, Heng Pan, Kai Lv, Zhenyu Li 等CCS 2026
- Breaking the Boundaries: Analyzing QUIC Frame-Packet Interactions With QUIC-AttackerNurullah Erinola, Marcel Maehren, Marcus Brinkmann, Jörg SchwenkUSENIX Security 2026
- SoK: Decoding the Enigma of Encrypted Network Traffic ClassifiersNimesha Wickramasinghe, Arash Shaghaghi, Gene Tsudik, Sanjay K. JhaS&P 2025
它引用的顶会 Paper1
相关 Paper
- Dissecting Performance of Production QUICAlexander Yu, Theophilus A. BensonWWW 2021 · 被引用 59 次
- A Security Model and Fully Verified Implementation for the IETF QUIC Record LayerAntoine Delignat-Lavaud, Cédric Fournet, Bryan Parno, Jonathan Protzenko 等S&P 2021 · 被引用 30 次
- QUIC is not Quick Enough over Fast InternetXumiao Zhang, Shuowei Jin, Yi He, Ahmad Hassan 等WWW 2024 · 被引用 32 次
- QCSD: A QUIC Client-Side Website-Fingerprinting Defence FrameworkJean-Pierre Smith, Luca Dolfi, Prateek Mittal, Adrian PerrigUSENIX Security 2022
- Loopy Hell(ow): Infinite Traffic Loops at the Application LayerYepeng Pan, Anna Ascheman, Christian RossowUSENIX Security 2024 · 被引用 4 次
