Revisiting QUIC attacks: a comprehensive review on QUIC security and a hands-on study

نویسندگان

چکیده

Abstract Built on top of UDP, the recently standardized QUIC protocol primarily aims to gradually replace TCP plus TLS HTTP/2 model. For instance, HTTP/3 is designed exploit QUIC’s features, including reduced connection establishment time, multiplexing without head line blocking, always-encrypted end-to-end security, and others. This work serves two key objectives. Initially, it offers first our knowledge full-fledged review security as seen through lens relevant literature so far. Second more importantly, extensive fuzz testing, we conduct a hands-on evaluation against six most popular QUIC-enabled production-grade servers. assessment identified several effective practical zero-day vulnerabilities, which, if exploited, can quickly overwhelm server resources. finding clear indication that fragmented production-level implementations this contemporary are not yet mature enough. Overall, at hand provides wholemeal appraisal from both empirical standpoint, therefore foreseen serve reference for future research in timely area.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

a study on rate making and required reserves determination in reinsurance market: a simulation

reinsurance is widely recognized as an important instrument in the capital management of an insurance company as well as its risk management tool. this thesis is intended to determine premium rates for different types of reinsurance policies. also, given the fact that the reinsurance coverage of every company depends upon its reserves, so different types of reserves and the method of their calc...

the relationship between eq, iq and test format: a study on test fairness

the major aim of this study was to investigate the relationship between iq, eq and test format in the light of test fairness considerations. this study took this relationship into account to see if people with different eq and iq performed differently on different test formats. to this end, 90 advanced learners of english form college of ferdowsi university of mashhad were chosen. they were ask...

15 صفحه اول

Taking a Long Look at QUIC

Google’s QUIC protocol, which implements TCP-like properties at the application layer atop a UDP transport, is now used by the vast majority of Chrome clients accessing Google properties but has no formal state machine specification, limited analysis, and ad-hoc evaluations based on snapshots of the protocol implementation in a small number of environments. Further frustrating attempts to evalu...

متن کامل

BIG & QUIC: Sparse Inverse Covariance Estimation for a Million Variables

The `1-regularized Gaussian maximum likelihood estimator (MLE) has been shown to have strong statistical guarantees in recovering a sparse inverse covariance matrix even under high-dimensional settings. However, it requires solving a difficult non-smooth log-determinant program with number of parameters scaling quadratically with the number of Gaussian variables. State-of-the-art methods thus d...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: International Journal of Information Security

سال: 2022

ISSN: ['1615-5262', '1615-5270']

DOI: https://doi.org/10.1007/s10207-022-00630-6