TY - GEN
T1 - The Design and Implementation of HTTP/3 DoS Prevention Technique on QUIC Initial Handshake
AU - Visoottiviseth, Vasaka
AU - Laosuwanwat, Pongpisit
AU - Rassameeroj, Ittipon
N1 - Publisher Copyright:
© 2025 IEEE.
PY - 2025
Y1 - 2025
N2 - The deployment of HTTP/3 powered by the QUIC protocol represents a significant advancement in the web technology. This paper investigates the vulnerabilities inherent in the QUIC protocol, particularly during its initial handshake phase, within the framework of Denial of Service (DoS) attacks that pose a threat to the infrastructure of HTTP/3. In this research, a Proof of Concept (POC) script is developed to emulate SYN Flood-like attacks to unveil the protocol's susceptibility to amplification and reflection attacks. Addressing these vulnerabilities, we also develop a signature for Suricata Intrusion Detection System (IDS) and evaluated its efficacy in detecting and mitigating the simulated attacks. The experimental results on a victim machine reveal a significant surge in CPU utilization-peaking at 100 % during nonprotected states and moderating to 49.95 % in protected states. Future research directions include refining these IDS rules and employing machine learning technologies for dynamic threat detection and adaptive rule optimization.
AB - The deployment of HTTP/3 powered by the QUIC protocol represents a significant advancement in the web technology. This paper investigates the vulnerabilities inherent in the QUIC protocol, particularly during its initial handshake phase, within the framework of Denial of Service (DoS) attacks that pose a threat to the infrastructure of HTTP/3. In this research, a Proof of Concept (POC) script is developed to emulate SYN Flood-like attacks to unveil the protocol's susceptibility to amplification and reflection attacks. Addressing these vulnerabilities, we also develop a signature for Suricata Intrusion Detection System (IDS) and evaluated its efficacy in detecting and mitigating the simulated attacks. The experimental results on a victim machine reveal a significant surge in CPU utilization-peaking at 100 % during nonprotected states and moderating to 49.95 % in protected states. Future research directions include refining these IDS rules and employing machine learning technologies for dynamic threat detection and adaptive rule optimization.
KW - DoS Attack
KW - HTTP/3
KW - Intrusion Detection System
KW - QUIC
UR - https://www.scopus.com/pages/publications/105007554448
U2 - 10.1109/KST65016.2025.11003302
DO - 10.1109/KST65016.2025.11003302
M3 - Conference contribution
AN - SCOPUS:105007554448
T3 - 2025 17th International Conference on Knowledge and Smart Technology, KST 2025
SP - 370
EP - 375
BT - 2025 17th International Conference on Knowledge and Smart Technology, KST 2025
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 17th International Conference on Knowledge and Smart Technology, KST 2025
Y2 - 26 February 2025 through 1 March 2025
ER -