首页    期刊浏览 2024年11月28日 星期四
登录注册

文章基本信息

  • 标题:Count Me If You Can: Enumerating QUIC Servers Behind Load Balancers
  • 本地全文:下载
  • 作者:Kashyap Thimmaraju ; Björn Scheuermann
  • 期刊名称:Electronic Communications of the EASST
  • 电子版ISSN:1863-2122
  • 出版年度:2021
  • 卷号:80
  • DOI:10.14279/tuj.eceasst.80.1172
  • 语种:English
  • 出版社:European Association of Software Science and Technology (EASST)
  • 摘要:QUIC is a new transport protocol over UDP which is recently became an IETF RFC. Our security analysis of the Connection ID mechanism in QUIC reveals that the protocol is underspecified. This allows an attacker to count the number of server instances behind a middlebox, e.g., a load balancer. We found 4/15 (~25%) implementations vulnerable to our enumeration attack. We then concretely describe how an attacker can count the number of instances behind a load balancer that either uses Round Robin or Hashing.
  • 关键词:QUIC;Security Analysis;Connection ID;Enumeration
国家哲学社会科学文献中心版权所有