상세 보기
Rescuing QUIC Flows From Countermeasures Against UDP Flooding Attacks
- Lee, Junseok;
- Kim, Minhyeong;
- Song, Wonjun;
- Kim, Younghoon;
- Kim, Dohyung
WEB OF SCIENCE
4SCOPUS
4초록
Due to advantages such as quick connection establishment and multiple streaming over a single connection, QUIC was included in the new standard of HTTP 3.0 as an alternative transport layer protocol. Since QUIC operates on UDP, however, QUIC flows can be blocked by existing countermeasures against UDP flooding attacks, even if transmission rates are fairly controlled by congestion control algorithms, such as TCP. In this paper, we confirm that such a problem arises in real-world Internet environment and design effective approaches to avoid it. In the first approach, the gateway router dynamically sets the rate limit for the QUIC flow, based on the expected next CWND size estimated by the receiver using a builtin congestion control algorithm. The second approach leverages the proactive dropping of packets (or ECN marking) to distinguish whether the flow is a self-regulated QUIC flow or an unresponsive UDP attack/selfish flow. Simulation studies using the ns-3 simulator confirm that the proposed approaches can selectively allow QUIC flows regardless of their short-term transmission rates while preserving the effectiveness of existing countermeasures against UDP flooding attacks.
키워드
- 제목
- Rescuing QUIC Flows From Countermeasures Against UDP Flooding Attacks
- 저자
- Lee, Junseok; Kim, Minhyeong; Song, Wonjun; Kim, Younghoon; Kim, Dohyung
- 발행일
- 2024
- 유형
- Proceedings Paper
- 저널명
- 39TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2024
- 페이지
- 1072 ~ 1080