dc.contributor.author |
Sudhan S., Hari Hara |
|
dc.contributor.author |
Kulkarni, Sameer G. |
|
dc.contributor.other |
IEEE 49th Conference on Local Computer Networks (LCN 2024) |
|
dc.coverage.spatial |
France |
|
dc.date.accessioned |
2024-09-20T05:26:15Z |
|
dc.date.available |
2024-09-20T05:26:15Z |
|
dc.date.issued |
2024-10-08 |
|
dc.identifier.citation |
Sudhan S., Hari Hara and Kulkarni, Sameer G., "Demo: security vulnerabilities and network service disruptions with HTTP/3", in the IEEE 49th Conference on Local Computer Networks (LCN 2024), Normandy, FR, Oct. 8-10, 2024. |
|
dc.identifier.uri |
https://doi.org/10.1109/LCN60385.2024.10639685 |
|
dc.identifier.uri |
https://repository.iitgn.ac.in/handle/123456789/10588 |
|
dc.description.abstract |
In this work, we meticulously examine and demonstrate the security vulnerabilities associated with HTTP/3 and the adversities it brings to the operations of the network services (middleboxes). HTTP/3 is built using the new QUIC transport protocol to introduce enhancements to web communication by leveraging the QUIC protocols secure and privacy focused features such as connection migration, passive latency monitoring, congestion control, flow control, and support for multiple streams.In the course of our investigation, we unveil unintended vulnerabilities inherent in the QUIC protocol. Specifically, we demonstrate that the passive latency monitoring feature in the QUIC protocol exposes a covert channel that can be exploited for reliable covert communication. Furthermore, we reveal that the QUIC connection migration feature disrupts the functionality of critical network functions, such as NAT/NAPT, leading to a denial-of-service vulnerability. We provide a practical demonstration of this denial-of-service vulnerability in a NAT network. Our findings highlight the need for comprehensive and robust security solutions to address the outlined vulnerabilities in HTTP/3. |
|
dc.description.statementofresponsibility |
by Hari Hara Sudhan S. and Sameer G. Kulkarni |
|
dc.language.iso |
en_US |
|
dc.publisher |
Institute of Electrical and Electronics Engineers (IEEE) |
|
dc.subject |
HTTP/3 |
|
dc.subject |
QUIC |
|
dc.subject |
Security |
|
dc.subject |
Covert Channel |
|
dc.subject |
Denail of Service (DoS) |
|
dc.subject |
Middlebox |
|
dc.subject |
NAT/NAPT |
|
dc.subject |
Loadbalancer |
|
dc.title |
Demo: security vulnerabilities and network service disruptions with HTTP/3 |
|
dc.type |
Conference Paper |
|