🤖 AI Summary
This study addresses the gap in existing QUIC protocol security analyses, which predominantly focus on network traffic and neglect empirical validation of defense mechanisms within binary implementations. To bridge this gap, we propose BSISA—a novel methodology that uniquely integrates binary reverse engineering with system-level network traffic analysis—to evaluate the real-world defensive efficacy of four major QUIC server implementations against six distinct attack types. By employing multidimensional classifiers and attack scenario simulation, BSISA precisely identifies “declared but silent” defense functions and pinpoints critical code paths responsible for attack absorption. Experimental results demonstrate that BSISA achieves an overall accuracy of 45.8%, substantially outperforming single-modality approaches, and uncover severe availability risks in certain implementations—most notably, picoquic exhibits a failure rate exceeding 72% under specific attacks.
📝 Abstract
The Quick UDP Internet Connections (QUIC) protocol is increasingly used to provide secure transport for Internet of Things (IoT) firmware and applications. Existing security analyses of QUIC focus on the captured network traffic, while binary-level analyses of QUIC implementations remain unexplored, leaving open the question of whether a defence specified by the QUIC standard is both present in the compiled binary and active when the server is under attack. This paper evaluates the Binary and System Integrated Security Analysis (BSISA) approach, in which a binary-level analysis of the compiled QUIC server is combined with a system-level analysis of the captured network traffic, on four production QUIC server implementations under six attack scenarios. Across 24 cells, the combined classifier configuration is the only configuration that correctly classifies at least one cell on every attack scenario, achieving 45.8% overall accuracy compared with 37.5% for the binary-level configuration and 25.0% for the system-level configuration. BSISA also identifies the specific defence function in the compiled binary that absorbed each attack, and flags declared-but-silent defences, routines that are present in the compiled binary (Retry-token validation in three of four stacks, anti-amplification in quiche) but never execute during attack, a class of finding that network capture alone cannot produce. In terms of efficiency, picoquic loses legitimate-client availability under slowloris and connection- ID exhaustion with failure rates of 72.4% and 73.3% respectively, while the other three implementations hold the failure rate at or below 0.5%. We hope these insights will be informative for QUIC security evaluations in IoT firmware deployments.