Exploiting Congestion Control Parameter Manipulation in QUIC for Security Implications
Y. A. Joarder, Surajit Sinha, Guillaume Doyen, Carol Fung · 2025
QUIC has emerged as a fundamental transport protocol for modern Internet infrastructure, serving as the foundation for HTTP/3. Although QUIC implements congestion control algorithms ($C C A$) to ensure fair network resource allocation, its user-space implementation architecture creates significant security vulnerabilities through accessible parameter manipulation. As transport layers become increasingly programmable, these vulnerabilities represent a broader security challenge for future network infrastructures where applications may deploy custom transport implementations. This paper presents a systematic analysis of selfish behaviors in QUIC through deliberate congestion control parameter (CCPM). Using the aioquic implementation, we experimentally demonstrate how strategic parameter manipulation in both NewReno and CUBIC algorithms provides substantial unfair bandwidth ($\boldsymbol{B} \boldsymbol{W}$) advantages. NewReno exhibits a major vulnerability with Loss Reduction Factor (LRF) and Congestion Avoidance Growth Rate (CAGR) manipulation, while CUBIC demonstrates better resilience, but remains exploitable, with combined LRF ($\beta_{\text {cubic }}$) and Maximum Idle Time (MIT) manipulations.