An Empirical Approach to Evaluate the Resilience of QUIC Protocol against Handshake Flood Attacks

被引:0
作者
Teyssier, Benjamin [1 ]
Joarder, Y. A. [1 ]
Fung, Carol [1 ]
机构
[1] Concordia Univ, Concordia Inst Informat Syst Engn CIISE, Montreal, PQ, Canada
来源
2023 19TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT, CNSM | 2023年
关键词
QUIC; TCP; DDoS; Amplification Factor; Syn Cookies; Syn Flood Attacks;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
QUIC is a new transport protocol aiming to enhance web connection performance and security. It was gaining popularity quickly in recent years and has been adopted by a number of prominent tech companies, including Facebook, Amazon, and Google. However, the resilience of QUIC Protocol against various cyber attacks has not been fully tested yet. In this paper, we investigate the resilience of QUIC Protocol against handshake flood attacks. We conducted comprehensive experiments to evaluate the resource consumptions of both the attacker and the target during incomplete handshake attacks, including CPU, memory, and bandwidth. The DDoS amplification factor was measured and analyzed based on the results. We compared the results against TCP Syn Cookies under Syn flood attacks. We show that the QUIC Protocol design has a much larger DDoS amplification factor compared to the TCP Syn Cookies, which means QUIC is more vulnerable to handshake DDoS attacks. Also, the CPU resource of QUIC servers is most likely the bottleneck during the handshake flood attacks. To the best of our knowledge, this is the first study to thoroughly investigate resilience of QUIC to handshake DDoS attacks.
引用
收藏
页数:9
相关论文
共 34 条
  • [1] [Anonymous], 2021, Tech. Rep. RFC9000
  • [2] [Anonymous], 2020, EPIQ 2020 P 2020 WOR
  • [3] Aumasson J.-P, 2012, Paper 2012/351
  • [4] Biswal P, 2016, IEEE GLOB COMM CONF
  • [5] Boeyen S., 2008, Request for Comments RFC 5280
  • [6] HTTP over UDP: an Experimental Investigation of QUIC
    Carlucci, Gaetano
    De Cicco, Luca
    Mascolo, Saverio
    [J]. 30TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, VOLS I AND II, 2015, : 609 - 614
  • [7] Cook S, 2017, IEEE ICC, DOI 10.1109/PLASMA.2017.8496097
  • [8] Cui Y, 2017, IEEE INTERNET COMPUT, V21, P72, DOI 10.1109/MIC.2017.44
  • [9] Eddy W., 2007, Tech. Rep, P19, DOI [10.17487/rfc4987, DOI 10.17487/RFC4987]
  • [10] F. incubator, 2019, mvfst