A Quic(k) Security Overview: A Literature Research on Implemented Security Recommendations

06/30/2023
by   Stefan Tatschner, et al.
0

Built on top of UDP, the relatively new QUIC protocol serves as the baseline for modern web protocol stacks. Equipped with a rich feature set, the protocol is defined by a 151 pages strong IETF standard complemented by several additional documents. Enabling fast updates and feature iteration, most QUIC implementations are implemented as user space libraries leading to a large and fragmented ecosystem. This work addresses the research question, "if a complex standard with a large number of different implementations leads to an insecure ecosystem?". The relevant RFC documents were studied and "Security Consideration" items describing conceptional problems were extracted. During the research, 13 popular production ready QUIC implementations were compared by evaluating 10 security considerations from RFC9000. While related studies mostly focused on the functional part of QUIC, this study confirms that available QUIC implementations are not yet mature enough from a security point of view.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/14/2020

MagicPairing: Apple's Take on Securing Bluetooth Peripherals

Device pairing in large Internet of Things (IoT) deployments is a challe...
research
09/07/2023

Security assessment of common open source MQTT brokers and clients

Security and dependability of devices are paramount for the IoT ecosyste...
research
09/07/2021

Implementing Security Protocol Monitors

Cryptographic protocols are often specified by narrations, i.e., finite ...
research
09/24/2018

Security and Performance Considerations in ROS 2: A Balancing Act

Robot Operating System (ROS) 2 is a ground-up re-design of ROS 1 to supp...
research
11/22/2022

The Security Protocol Verifier ProVerif and its Horn Clause Resolution Algorithm

ProVerif is a widely used security protocol verifier. Internally, ProVer...
research
06/15/2020

The EMV Standard: Break, Fix, Verify

EMV is the international protocol standard for smartcard payment and is ...
research
07/24/2019

No More Chasing Waterfalls: A Measurement Study of the Header Bidding Ad-Ecosystem

In the last few years, Header Bidding (HB) has gained popularity among w...

Please sign up or login with your details

Forgot password? Click here to reset