Assessing Initial Attacks and Defense with Retry Function in MQTT Over QUIC

Shin Hitomi, Ismail Arai, Arata Endo, Masatoshi Kakiuchi, Kazutoshi Fujikawa · 2024

MQTT over QUIC protocol has recently garnered attention in the IoT field. This protocol enables faster communication than the traditional MQTT. However, the security risks arising from the new combination of MQTT and QUIC still need to be explained. In particular, the MQTT over QUIC broker's availability could be compromised by initial attacks that exploit specific vulnerabilities of the QUIC protocol. Initial attacks target the handshake process of the QUIC protocol and unfairly consume server-side resources. This study examines the impact of initial attacks on MQTT over QUIC brokers and proposes defensive measures. Our verification shows that initial attacks can indeed compromise the availability of MQTT over QUIC brokers. Furthermore, we confirmed that maintaining session continuity can preserve broker availability against initial attacks.

Read the paper · More papers on PaperTik