Manipulated Client Initial Attack and Defense of QUIC

Bo Cui, Zixuan Li, Fei Richard Yu · 2022

The Quick UDP Internet Connection (QUIC) protocol represents one of the most promising transport layer solutions to accelerate HTTP traffic after years of evolution. It has become a standard of the Internet Engineering Task Force (IETF) and is gaining worldwide popularity. Compared to its counterpart TCP+TLS solution, QUIC reduces the latency of connection establishment by integrating key exchange operations into the initial handshake. Its UDP foundation and user-space implementation also contribute to its deployability and evolv-ability. However, the renowned 1-RTT handshake mechanism is still susceptible to first-flight attacks. In this paper, we propose a new type of denial-of-service (DoS) attack against QUIC by manipulating client initial packets. This attack can exhaust massive computing resources on the receiving side with approximately 85% throughput degradation per-core compared to the standard data path. To clarify the feasibility and impact of this attack, we provide a comprehensive analysis of initial packet cryptographic schemes and a performance profiling of five typical QUIC implementations. In addition, we investigate an effective method for mitigating this attack using the existing Network Acceleration Complex (NAC) in Intel Snow Ridge SoC. This practice can achieve anti-Dos capability of 67Gbps versus a typical Xeon core of ~0.5Gbps, which suggests that inline hardware offloading can be a viable means of resolving conflicts between latency reduction and security assurance.

Read the paper · More papers on PaperTik