A QUIC(K) Way Through Your Firewall?

07/13/2021
by   Konrad Yuri Gbur, et al.
0

The QUIC protocol is a new approach to combine encryption and transport layer stream abstraction into one protocol to lower latency and improve security. However, the decision to encrypt transport layer functionality may limit the capabilities of firewalls to protect networks. To identify these limitations we created a test environment and analyzed generated QUIC traffic from the viewpoint of a middlebox. This paper shows that QUIC indeed exposes traditional stateful firewalls to UDP hole punching bypass attacks. On the contrary we show the robustness against censorship of QUIC through the encrypted transport layer design and analyze the capabilities to re-gain stateful tracking capabilities by deep packet inspection of the few exposed QUIC header fields.

READ FULL TEXT

page 1

page 5

research
11/22/2022

Analysis of the DoIP Protocol for Security Vulnerabilities

DoIP, which is defined in ISO 13400, is a transport protocol stack for d...
research
04/08/2018

TCP Decoupling for Next Generation Communication System

In traditional networks, interfaces of network nodes are duplex. But, em...
research
02/15/2021

Beyond QUIC v1 – A First Look at Recent Transport Layer IETF Standardization Efforts

The transport layer is ossified. With most of the research and deploymen...
research
10/03/2022

It's Time to Replace TCP in the Datacenter

In spite of its long and successful history, TCP is a poor transport pro...
research
12/09/2019

Attacks on Dynamic Protocol Detection of Open Source Network Security Monitoring Tools

Protocol detection is the process of determining the application layer p...
research
12/06/2021

Tracking the QUIC Spin Bit on Tofino

QUIC offers security and privacy for modern web traffic by closely integ...
research
04/02/2019

DNS-Morph: UDP-Based Bootstrapping Protocol For Tor

Tor is one of the most popular systems for anonymous communication and c...

Please sign up or login with your details

Forgot password? Click here to reset