QShield: Universal Defense Framework Against QUIC Client-Side Attacks with eBPF

Yulin Ni, E Yuepeng, Jingguo Ge, Bingzhen Wu · 2025

QUIC adapts well to complex network situations due to mechanisms such as 0/1-RTT handshake and fast retransmission. It has now become a new star in the era of IoT. However, a phenomenon reveals the security risks of QUIC. Studies indicate that the internet is exposed to an average of four QUIC flood attacks per hour. The efficiency-oriented features of QUIC introduce vulnerabilities, making it particularly susceptible to attacks. In IoT scenarios, protocol security often depends on the design of the protocol itself and the middlewares. However, QUIC's design does not prioritize security as its highest concern and due to the ossification of middleboxes, the server-side defense is the only option. Therefore, we propose the QShield framework to seek breakthroughs from an engineering perspective. Based on the SDN principles, QShield consists of three parts. At the application layer, QUIC applications can utilize this library to implement strategy development and enable data sharing. A user-space library operates as the control layer, facilitating real-time bidirectional data transfers between the kernel and user space via a suite of APIs. In the data layer, QShield core blocks attack packets at the lowest layer of the Linux network protocol stack using eBPF technology. QShield effectively resists client-side attacks, and experimental results show that QShield can reduce the server's CPU usage for processing attack packets by nearly 50%, thereby essentially restoring normal Queries Per Second and bandwidth, reducing the bandwidth amplification by about 68% on the specific QUIC implementation.

Read the paper · More papers on PaperTik