A Quic(k) Security Overview: A Literature Research on Implemented Security Recommendations

被引:3
作者
Tatschner, Stefan [1 ,2 ]
Peters, Sebastian N. [1 ]
Emeis, David [1 ]
Morris, John [2 ]
Newe, Thomas [2 ]
机构
[1] Fraunhofer Inst AISEC, Garching, Germany
[2] Univ Limerick, Limerick, Ireland
来源
18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023 | 2023年
关键词
QUIC; RFC9000; security considerations; web;
D O I
10.1145/3600160.3605164
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Built on top of UDP, the relatively new QUIC protocol serves as the baseline for modern web protocol stacks. Equipped with a rich feature set, the protocol is defined by a 151 pages strong IETF stan-dard complemented by several additional documents. Enabling fast updates and feature iteration, most QUIC implementations are im-plemented as user space libraries leading to a large and fragmented ecosystem. This work addresses the research question, "if a complex standard with a large number of different implementations leads to an insecure ecosystem?". The relevant RFC documents were studied and "Security Consideration" items describing conceptional prob-lems were extracted. During the research, 13 popular production ready QUIC implementations were compared by evaluating 10 se-curity considerations from RFC9000. While related studies mostly focused on the functional part of QUIC, this study confirms that available QUIC implementations are not yet mature enough from a security point of view.
引用
收藏
页数:16
相关论文
共 30 条
  • [21] Rescorla E., 2018, RFC 8446, DOI DOI 10.17487/RFC8446
  • [22] Rescorla Eric, 2023, RFC 3552
  • [23] Schinazi David, 2022, Compati-ble Version Negotiation for QUIC. Internet-Draft draft-ietfquic-version-negotiation-14
  • [24] Sherwood R., 2005, CCS 05 P 12 ACM C CO, P383
  • [25] Statista, 2023, Number of internet users in India from 2010 to 2023, with estimates until 2050
  • [26] Stewart Randall R., 2010, RFC 5961, DOI [10.17487/RFC5961, DOI 10.17487/RFC5961]
  • [27] Thomson M., 2022, HTTP/2. RFC 9113, DOI [10.17487/RFC9113, DOI 10.17487/RFC9113]
  • [28] Thomson Martin, 2021, RFC 9001, DOI DOI 10.17487/RFC9001
  • [29] Thomson Martin, 2021, RFC 8999, DOI DOI 10.17487/RFC8999
  • [30] Implementation and Performance Evaluation of the QUIC Protocol in Linux Kernel
    Wang, Peng
    Bianco, Carmine
    Riihijarvi, Janne
    Petrova, Marina
    [J]. MSWIM'18: PROCEEDINGS OF THE 21ST ACM INTERNATIONAL CONFERENCE ON MODELING, ANALYSIS AND SIMULATION OF WIRELESS AND MOBILE SYSTEMS, 2018, : 227 - 234