Demo: security vulnerabilities and network service disruptions with HTTP/3

Show simple item record

dc.contributor.author Sudhan S., Hari Hara
dc.contributor.author Kulkarni, Sameer G.
dc.contributor.other IEEE 49th Conference on Local Computer Networks (LCN 2024)
dc.coverage.spatial France
dc.date.accessioned 2024-09-20T05:26:15Z
dc.date.available 2024-09-20T05:26:15Z
dc.date.issued 2024-10-08
dc.identifier.citation Sudhan S., Hari Hara and Kulkarni, Sameer G., "Demo: security vulnerabilities and network service disruptions with HTTP/3", in the IEEE 49th Conference on Local Computer Networks (LCN 2024), Normandy, FR, Oct. 8-10, 2024.
dc.identifier.uri https://doi.org/10.1109/LCN60385.2024.10639685
dc.identifier.uri https://repository.iitgn.ac.in/handle/123456789/10588
dc.description.abstract In this work, we meticulously examine and demonstrate the security vulnerabilities associated with HTTP/3 and the adversities it brings to the operations of the network services (middleboxes). HTTP/3 is built using the new QUIC transport protocol to introduce enhancements to web communication by leveraging the QUIC protocols secure and privacy focused features such as connection migration, passive latency monitoring, congestion control, flow control, and support for multiple streams.In the course of our investigation, we unveil unintended vulnerabilities inherent in the QUIC protocol. Specifically, we demonstrate that the passive latency monitoring feature in the QUIC protocol exposes a covert channel that can be exploited for reliable covert communication. Furthermore, we reveal that the QUIC connection migration feature disrupts the functionality of critical network functions, such as NAT/NAPT, leading to a denial-of-service vulnerability. We provide a practical demonstration of this denial-of-service vulnerability in a NAT network. Our findings highlight the need for comprehensive and robust security solutions to address the outlined vulnerabilities in HTTP/3.
dc.description.statementofresponsibility by Hari Hara Sudhan S. and Sameer G. Kulkarni
dc.language.iso en_US
dc.publisher Institute of Electrical and Electronics Engineers (IEEE)
dc.subject HTTP/3
dc.subject QUIC
dc.subject Security
dc.subject Covert Channel
dc.subject Denail of Service (DoS)
dc.subject Middlebox
dc.subject NAT/NAPT
dc.subject Loadbalancer
dc.title Demo: security vulnerabilities and network service disruptions with HTTP/3
dc.type Conference Paper


Files in this item

Files Size Format View

There are no files associated with this item.

This item appears in the following Collection(s)

Show simple item record

Search Digital Repository


Browse

My Account