Skip to main navigation Skip to search Skip to main content

The Design and Implementation of HTTP/3 DoS Prevention Technique on QUIC Initial Handshake

  • Mahidol University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The deployment of HTTP/3 powered by the QUIC protocol represents a significant advancement in the web technology. This paper investigates the vulnerabilities inherent in the QUIC protocol, particularly during its initial handshake phase, within the framework of Denial of Service (DoS) attacks that pose a threat to the infrastructure of HTTP/3. In this research, a Proof of Concept (POC) script is developed to emulate SYN Flood-like attacks to unveil the protocol's susceptibility to amplification and reflection attacks. Addressing these vulnerabilities, we also develop a signature for Suricata Intrusion Detection System (IDS) and evaluated its efficacy in detecting and mitigating the simulated attacks. The experimental results on a victim machine reveal a significant surge in CPU utilization-peaking at 100 % during nonprotected states and moderating to 49.95 % in protected states. Future research directions include refining these IDS rules and employing machine learning technologies for dynamic threat detection and adaptive rule optimization.

Original languageEnglish
Title of host publication2025 17th International Conference on Knowledge and Smart Technology, KST 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages370-375
Number of pages6
ISBN (Electronic)9798331520403
DOIs
Publication statusPublished - 2025
Event17th International Conference on Knowledge and Smart Technology, KST 2025 - Bangkok, Thailand
Duration: 26 Feb 20251 Mar 2025

Publication series

Name2025 17th International Conference on Knowledge and Smart Technology, KST 2025

Conference

Conference17th International Conference on Knowledge and Smart Technology, KST 2025
Country/TerritoryThailand
CityBangkok
Period26/02/251/03/25

Keywords

  • DoS Attack
  • HTTP/3
  • Intrusion Detection System
  • QUIC

Fingerprint

Dive into the research topics of 'The Design and Implementation of HTTP/3 DoS Prevention Technique on QUIC Initial Handshake'. Together they form a unique fingerprint.

Cite this