• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. A Quic(k) Security Overview: A Literature Research on Implemented Security Recommendations
 
  • Details
  • Full
Options
2023
Conference Paper
Title

A Quic(k) Security Overview: A Literature Research on Implemented Security Recommendations

Abstract
Built on top of UDP, the relatively new QUIC protocol serves as the baseline for modern web protocol stacks. Equipped with a rich feature set, the protocol is defined by a 151 pages strong IETF standard complemented by several additional documents. Enabling fast updates and feature iteration, most QUIC implementations are implemented as user space libraries leading to a large and fragmented ecosystem. This work addresses the research question, "if a complex standard with a large number of different implementations leads to an insecure ecosystem?". The relevant RFC documents were studied and "Security Consideration"items describing conceptional problems were extracted. During the research, 13 popular production ready QUIC implementations were compared by evaluating 10 security considerations from RFC9000. While related studies mostly focused on the functional part of QUIC, this study confirms that available QUIC implementations are not yet mature enough from a security point of view.
Author(s)
Tatschner, Stefan  
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Peters, Sebastian  orcid-logo
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Emeis, David
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Morris, John
Newe, Thomas
Mainwork
ARES 2023, the 18th International Conference on Availability, Reliability and Security. Proceedings  
Conference
International Conference on Availability, Reliability and Security 2023  
Open Access
DOI
10.1145/3600160.3605164
Additional full text version
Landing Page
Language
English
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Keyword(s)
  • QUIC

  • RFC9000

  • security considerations

  • web

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024