How Resilient is QUIC to Security and Privacy Attacks?

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Sengupta, Jayasree, Dey, Debasmita, Ferlin-Reiter, Simone, Ghosh, Nirnay, Bajpai, Vaibhav
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866912459021877248
author Sengupta, Jayasree
Dey, Debasmita
Ferlin-Reiter, Simone
Ghosh, Nirnay
Bajpai, Vaibhav
author_facet Sengupta, Jayasree
Dey, Debasmita
Ferlin-Reiter, Simone
Ghosh, Nirnay
Bajpai, Vaibhav
contents QUIC has rapidly evolved into a cornerstone transport protocol for secure, low-latency communications, yet its deployment continues to expose critical security and privacy vulnerabilities, particularly during connection establishment phases and via traffic analysis. This paper systematically revisits a comprehensive set of attacks on QUIC and emerging privacy threats. Building upon these observations, we critically analyze recent IETF mitigation efforts, including TLS Encrypted Client Hello (ECH), Oblivious HTTP (OHTTP) and MASQUE. We analyze how these mechanisms enhance privacy while introducing new operational risks, particularly under adversarial load. Additionally, we discuss emerging challenges posed by post-quantum cryptographic (PQC) handshakes, including handshake expansion and metadata leakage risks. Our analysis highlights ongoing gaps between theoretical defenses and practical deployments, and proposes new research directions focused on adaptive privacy mechanisms. Building on these insights, we propose future directions to ensure long-term security of QUIC and aim to guide its evolution as a robust, privacy-preserving, and resilient transport foundation for the next-generation Internet.
format Preprint
id arxiv_https___arxiv_org_abs_2401_06657
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle How Resilient is QUIC to Security and Privacy Attacks?
Sengupta, Jayasree
Dey, Debasmita
Ferlin-Reiter, Simone
Ghosh, Nirnay
Bajpai, Vaibhav
Cryptography and Security
Networking and Internet Architecture
QUIC has rapidly evolved into a cornerstone transport protocol for secure, low-latency communications, yet its deployment continues to expose critical security and privacy vulnerabilities, particularly during connection establishment phases and via traffic analysis. This paper systematically revisits a comprehensive set of attacks on QUIC and emerging privacy threats. Building upon these observations, we critically analyze recent IETF mitigation efforts, including TLS Encrypted Client Hello (ECH), Oblivious HTTP (OHTTP) and MASQUE. We analyze how these mechanisms enhance privacy while introducing new operational risks, particularly under adversarial load. Additionally, we discuss emerging challenges posed by post-quantum cryptographic (PQC) handshakes, including handshake expansion and metadata leakage risks. Our analysis highlights ongoing gaps between theoretical defenses and practical deployments, and proposes new research directions focused on adaptive privacy mechanisms. Building on these insights, we propose future directions to ensure long-term security of QUIC and aim to guide its evolution as a robust, privacy-preserving, and resilient transport foundation for the next-generation Internet.
title How Resilient is QUIC to Security and Privacy Attacks?
topic Cryptography and Security
Networking and Internet Architecture
url https://arxiv.org/abs/2401.06657