The Design and Implementation of HTTP/3 DoS Prevention Technique on QUIC Initial Handshake

dc.contributor.authorVisoottiviseth V.
dc.contributor.authorLaosuwanwat P.
dc.contributor.authorRassameeroj I.
dc.contributor.correspondenceVisoottiviseth V.
dc.contributor.otherMahidol University
dc.date.accessioned2025-06-14T18:07:59Z
dc.date.available2025-06-14T18:07:59Z
dc.date.issued2025-01-01
dc.description.abstractThe deployment of HTTP/3 powered by the QUIC protocol represents a significant advancement in the web technology. This paper investigates the vulnerabilities inherent in the QUIC protocol, particularly during its initial handshake phase, within the framework of Denial of Service (DoS) attacks that pose a threat to the infrastructure of HTTP/3. In this research, a Proof of Concept (POC) script is developed to emulate SYN Flood-like attacks to unveil the protocol's susceptibility to amplification and reflection attacks. Addressing these vulnerabilities, we also develop a signature for Suricata Intrusion Detection System (IDS) and evaluated its efficacy in detecting and mitigating the simulated attacks. The experimental results on a victim machine reveal a significant surge in CPU utilization-peaking at 100 % during nonprotected states and moderating to 49.95 % in protected states. Future research directions include refining these IDS rules and employing machine learning technologies for dynamic threat detection and adaptive rule optimization.
dc.identifier.citation2025 17th International Conference on Knowledge and Smart Technology Kst 2025 (2025) , 370-375
dc.identifier.doi10.1109/KST65016.2025.11003302
dc.identifier.scopus2-s2.0-105007554448
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/123456789/110697
dc.rights.holderSCOPUS
dc.subjectBusiness, Management and Accounting
dc.subjectComputer Science
dc.subjectDecision Sciences
dc.titleThe Design and Implementation of HTTP/3 DoS Prevention Technique on QUIC Initial Handshake
dc.typeConference Paper
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=105007554448&origin=inward
oaire.citation.endPage375
oaire.citation.startPage370
oaire.citation.title2025 17th International Conference on Knowledge and Smart Technology Kst 2025
oairecerif.author.affiliationMahidol University

Files

Collections