Exploring QUIC Security and Privacy: A Comprehensive Survey on QUIC Security and Privacy Vulnerabilities, Threats, Attacks, and Future Research Directions

被引:2
作者
Joarder, Y. A. [1 ]
Fung, Carol [1 ]
机构
[1] Concordia Univ, Concordia Inst Informat Syst Engn, Montreal, PQ H3G 1M8, Canada
来源
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT | 2024年 / 21卷 / 06期
关键词
QUIC; survey; network security; privacy; sustainable Internet; HTTP/3; TLS; 1.3; network protocol; transport layer protocol; TCP; UDP; network sustainability; protocol security & privacy; risks; vulnerabilities; threats; attacks; Internet protocol;
D O I
10.1109/TNSM.2024.3457858
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
QUIC is a modern transport protocol aiming to improve Web connection performance and security. It is the transport layer for HTTP/3. QUIC offers numerous advantages over traditional transport layer protocols, such as TCP and UDP, including reduced latency, improved congestion control, connection migration and encryption by default. However, these benefits introduce new security and privacy challenges that need to be addressed, as cyber attackers can exploit weaknesses in the protocol. QUIC's security and privacy issues have been largely unexplored, as existing research on QUIC primarily focuses on performance upgrades. This survey paper addresses the knowledge gap in QUIC's security and privacy challenges while proposing directions for future research to enhance its security and privacy. Our comprehensive analysis covers QUIC's history, architecture, core mechanisms (such as cryptographic design and handshaking process), security model, and threat landscape. We examine QUIC's significant vulnerabilities, critical security and privacy attacks, emerging threats, advanced security and privacy challenges, and mitigation strategies. Furthermore, we outline future research directions to improve QUIC's security and privacy. By exploring the protocol's security and privacy implications, this paper informs decision-making processes and enhances online safety for users and professionals. Our research identifies key risks, vulnerabilities, threats, and attacks targeting QUIC, providing actionable insights to strengthen the protocol. Through this comprehensive analysis, we contribute to developing and deploying a faster, more secure next-generation Internet infrastructure. We hope this investigation serves as a foundation for future Internet security and privacy innovations, ensuring robust protection for modern digital communications.
引用
收藏
页码:6953 / 6973
页数:21
相关论文
共 112 条
[1]  
Aboba B. D., 2023, RFC 9443
[2]  
Akbari Azirani I., 2021, M.S. thesis
[3]  
[Anonymous], 2023, QUIC
[4]  
[Anonymous], 2024, Usage statistics of QUIC for websites
[5]  
Arfaoui G., 2019, 2019749 CRYPT EPRINT
[6]   Nonce reuse/misuse resistance authentication encryption schemes for modern TLS cipher suites and QUIC based web servers [J].
Arunkumar, B. ;
Kousalya, G. .
JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2020, 38 (05) :6483-6493
[7]  
Aviram N, 2016, PROCEEDINGS OF THE 25TH USENIX SECURITY SYMPOSIUM, P689
[8]  
AWS Security Blog, 2022, Enable PostQuantum Key Exchange in QUIC With The S2N-QUIC Library
[9]  
Balachandran A, 2023, LECT N MOBIL, P85, DOI [10.1007/978-3-031-11112-9_8, 10.1007/978-981-99-1312-1_7]
[10]   QuicTor: Enhancing Tor for Real-Time Communication Using QUIC Transport Protocol [J].
Basyoni, Lamiaa ;
Erbad, Aiman ;
Alsabah, Mashael ;
Fetais, Noora ;
Mohamed, Amr ;
Guizani, Mohsen .
IEEE ACCESS, 2021, 9 :28769-28784