Rescuing QUIC Flows From Countermeasures Against UDP Flooding Attacks

Citations

WEB OF SCIENCE

4
Citations

SCOPUS

4

초록

Due to advantages such as quick connection establishment and multiple streaming over a single connection, QUIC was included in the new standard of HTTP 3.0 as an alternative transport layer protocol. Since QUIC operates on UDP, however, QUIC flows can be blocked by existing countermeasures against UDP flooding attacks, even if transmission rates are fairly controlled by congestion control algorithms, such as TCP. In this paper, we confirm that such a problem arises in real-world Internet environment and design effective approaches to avoid it. In the first approach, the gateway router dynamically sets the rate limit for the QUIC flow, based on the expected next CWND size estimated by the receiver using a builtin congestion control algorithm. The second approach leverages the proactive dropping of packets (or ECN marking) to distinguish whether the flow is a self-regulated QUIC flow or an unresponsive UDP attack/selfish flow. Simulation studies using the ns-3 simulator confirm that the proposed approaches can selectively allow QUIC flows regardless of their short-term transmission rates while preserving the effectiveness of existing countermeasures against UDP flooding attacks.

키워드

UDP flooding attacksSelf-regulated QUIC flowsNetwork securityreceiver-side RTT estimation in QUIC
제목
Rescuing QUIC Flows From Countermeasures Against UDP Flooding Attacks
저자
Lee, JunseokKim, MinhyeongSong, WonjunKim, YounghoonKim, Dohyung
DOI
10.1145/3605098.3635885
발행일
2024
유형
Proceedings Paper
저널명
39TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2024
페이지
1072 ~ 1080