{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T17:03:37Z","timestamp":1785603817843,"version":"3.56.0"},"reference-count":79,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2022,12,2]],"date-time":"2022-12-02T00:00:00Z","timestamp":1669939200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,12,2]],"date-time":"2022-12-02T00:00:00Z","timestamp":1669939200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100007778","name":"Aegean University","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100007778","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2023,4]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Built on top of UDP, the recently standardized QUIC protocol primarily aims to gradually replace the TCP plus TLS plus HTTP\/2 model. For instance, HTTP\/3 is designed to exploit QUIC\u2019s features, including reduced connection establishment time, multiplexing without head of line blocking, always-encrypted end-to-end security, and others. This work serves two key objectives. Initially, it offers the first to our knowledge full-fledged review on QUIC security as seen through the lens of the relevant literature so far. Second and more importantly, through extensive fuzz testing, we conduct a hands-on security evaluation against the six most popular QUIC-enabled production-grade servers. This assessment identified several effective and practical zero-day vulnerabilities, which, if exploited, can quickly overwhelm the server resources. This finding is a clear indication that the fragmented production-level implementations of this contemporary protocol are not yet mature enough. Overall, the work at hand provides the first wholemeal appraisal of QUIC security from both a literature review and empirical standpoint, and it is therefore foreseen to serve as a reference for future research in this timely area.<\/jats:p>","DOI":"10.1007\/s10207-022-00630-6","type":"journal-article","created":{"date-parts":[[2022,12,2]],"date-time":"2022-12-02T04:05:02Z","timestamp":1669953902000},"page":"347-365","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":28,"title":["Revisiting QUIC attacks: a comprehensive review on QUIC security and a hands-on study"],"prefix":"10.1007","volume":"22","author":[{"given":"Efstratios","family":"Chatzoglou","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vasileios","family":"Kouliaridis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Georgios","family":"Karopoulos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6348-5031","authenticated-orcid":false,"given":"Georgios","family":"Kambourakis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,12,2]]},"reference":[{"key":"630_CR1","doi-asserted-by":"publisher","unstructured":"Belshe, M., Peon, R., Thomson, M.: Hypertext Transfer Protocol Version 2 (HTTP\/2). RFC 7540. (2015). https:\/\/doi.org\/10.17487\/RFC7540. https:\/\/www.rfc-editor.org\/info\/rfc7540","DOI":"10.17487\/RFC7540"},{"key":"630_CR2","doi-asserted-by":"publisher","unstructured":"Langley, A., et al.: The QUIC transport protocol: design and internet-scale deployment. In: Proceedings of the Conference of the ACM Special Interest Group on Data Communication. SIGCOMM\u201917. Association for Computing Machinery, Los Angeles, pp. 183\u2013196 (2017). https:\/\/doi.org\/10.1145\/3098822.3098842","DOI":"10.1145\/3098822.3098842"},{"key":"630_CR3","doi-asserted-by":"publisher","unstructured":"Iyengar, J., Thomson, M.: QUIC: a UDP-based multiplexed and secure transport. RFC 9000. (2021). https:\/\/doi.org\/10.17487\/RFC9000. https:\/\/www.rfc-editor.org\/info\/rfc9000","DOI":"10.17487\/RFC9000"},{"key":"630_CR4","doi-asserted-by":"publisher","unstructured":"Thomson, M., Turner, S.: Using TLS to secure QUIC. RFC 9001. (2021). https:\/\/doi.org\/10.17487\/RFC9001. https:\/\/www.rfc-editor.org\/info\/rfc9001","DOI":"10.17487\/RFC9001"},{"key":"630_CR5","unstructured":"Bishop, M.: Hypertext transfer protocol Version 3 (HTTP\/3). Internet-Draft draft-ietf-quichttp- 34. Work in Progress. Internet Engineering Task Force, p. 75 (2021). https:\/\/datatracker.ietf.org\/doc\/html\/draft-ietf-quic-http-34"},{"key":"630_CR6","unstructured":"Joras, M.. Chi, Y.: How Facebook is bringing QUIC to billions. last visited 03\/11\/2021. https:\/\/engineering.fb.com\/2020\/10\/21\/networking-traffic\/how-facebook-isbringing-quic-to-billions\/"},{"key":"630_CR7","unstructured":"LSQUIC.: LiteSpeed QUIC and HTTP\/3 Library. Visited on 2022-02-15. https:\/\/github.com\/litespeedtech\/lsquic"},{"key":"630_CR8","unstructured":"W3Techs: Usage statistics of QUIC for websites. Last visited 29\/03\/2022. https:\/\/w3techs.com\/technologies\/details\/ce-quic"},{"key":"630_CR9","unstructured":"W3Techs: Usage statistics of HTTP\/3 for websites. Last visited 29\/03\/2022. https:\/\/w3techs.com\/technologies\/details\/ce-http3"},{"key":"630_CR10","unstructured":"Langley, A., Chang, W.-T.: QUIC Crypto. Last visited 31\/03\/2022. https:\/\/docs.google.com\/document\/d\/1g5nIXAIkN_Y-7XJW5K45IblHd_L2f5LTaDUDwvZ5L6g\/edit#"},{"key":"630_CR11","doi-asserted-by":"publisher","unstructured":"Rescorla, E., Korver, B.: Guidelines for writing RFC text on security considerations. RFC 3552. (2003). https:\/\/doi.org\/10.17487\/RFC3552. https:\/\/www.rfc-editor.org\/info\/rfc3552","DOI":"10.17487\/RFC3552"},{"key":"630_CR12","unstructured":"Snake, R., Kinsella, J., Gonzalez, H., Lee, R.E.: Slowloris HTTP DoS. Visited on 2022-04-04. https:\/\/web.archive.org\/web\/20150426090206\/http:\/\/ha.ckers.org\/slowloris\/"},{"key":"630_CR13","unstructured":"quic-go: A QUIC implementation in pure go. Visited on 2022-02-15. https:\/\/github.com\/lucas-clemente\/quic-go"},{"key":"630_CR14","unstructured":"quiche: Savoury implementation of the QUIC transport protocol and HTTP\/3. Visited on 2022- 02-15. https:\/\/github.com\/cloudflare\/quiche"},{"key":"630_CR15","unstructured":"nghttp2: nghttp2\u2014HTTP\/2 C library and tools. Visited on 2022-02-15. https:\/\/github.com\/nghttp2\/nghttp2"},{"key":"630_CR16","unstructured":"msquic: Cross-platform, C implementation of the IETF QUIC protocol. Visited on 2022-02-15. https:\/\/github.com\/microsoft\/msquic.19"},{"key":"630_CR17","unstructured":"quinn: Async-friendly QUIC implementation in Rust. Visited on 2022-02-15. https:\/\/github.com\/quinn-rs\/quinn"},{"key":"630_CR18","unstructured":"reactor-netty: TCP\/HTTP\/UDP\/QUIC client\/server with Reactor over Netty. Visited on 2022-02-15. https:\/\/github.com\/reactor\/reactor-netty"},{"key":"630_CR19","unstructured":"neqo: neqo\u2014a QUIC library with Mozilla cooperation. Visited on 2022-02-15. https:\/\/github.com\/mozilla\/neqo"},{"key":"630_CR20","unstructured":"mvfst: An implementation of the QUIC transport protocol. Visited on 2022-02-15. https:\/\/github.com\/facebookincubator\/mvfst"},{"key":"630_CR21","unstructured":"xquic: XQUIC Library released by Alibaba is a cross-platform implementation of QUIC and HTTP\/3 protocol. Visited on 2022-02-15. https:\/\/github.com\/alibaba\/xquic"},{"key":"630_CR22","unstructured":"aioquic: QUIC and HTTP\/3 implementation in Python. Visited on 2022-02-15. https:\/\/github.com\/aiortc\/aioquic"},{"key":"630_CR23","unstructured":"ngtcp2: ngtcp2 project is an effort to implement IETF QUIC protocol. Visited on 2022-02-15. https:\/\/github.com\/ngtcp2\/ngtcp2"},{"key":"630_CR24","unstructured":"s2n-quic: AWS | An implementation of the IETF QUIC protocol. Visited on 2022-02-17. https:\/\/github.com\/aws\/s2n-quic"},{"key":"630_CR25","unstructured":"quicly: A modular QUIC stack designed primarily for H2O. Visited on 2022-02-15. https:\/\/github.com\/h2o\/quicly"},{"key":"630_CR26","unstructured":"picoquic: Minimal implementation of the QUIC protocol. Visited on 2022-02-15. https:\/\/github.com\/private-octopus\/picoquic"},{"key":"630_CR27","unstructured":"kwik: A QUIC client, client library and server implementation in Java. Supports HTTP3 with \u201cFlupke\u201d add-on. Visited on 2022-02-15. https:\/\/github.com\/ptrd\/kwik"},{"key":"630_CR28","unstructured":"quiche google: Google\u2019s production-ready implementation of QUIC, HTTP\/2, and HTTP\/3. Visited on 2022-02-17. https:\/\/github.com\/google\/quiche"},{"key":"630_CR29","unstructured":"nginx: A QUIC server implementation for NGINX. Visited on 2022-02-15. https:\/\/hg.nginx.org\/nginx-quic\/shortlog\/quic"},{"key":"630_CR30","doi-asserted-by":"crossref","unstructured":"Sakurada, H., et al.: Analyzing and Fixing the QACCE Security of QUIC. In: Lidong, C., David, M., Chris, M. (eds.), Security Standardisation Research. Springer, Cham pp. 1\u201331 (2016)","DOI":"10.1007\/978-3-319-49100-4_1"},{"key":"630_CR31","doi-asserted-by":"publisher","unstructured":"Lychev, R., et al.: How secure and quick is QUIC? Provable security and performance analyses. In: 2015 IEEE Symposium on Security and Privacy. (2015), pp. 214\u2013231. https:\/\/doi.org\/10.1109\/SP.2015.21","DOI":"10.1109\/SP.2015.21"},{"key":"630_CR32","doi-asserted-by":"crossref","unstructured":"Chen, S. et al.: Secure Communication Channel Establishment: TLS 1.3 (over TCP Fast Open) vs. QUIC. In: Kazue, S., Steve, S., Peter, Y.A., Ryan (eds.), Computer Security\u2014ESORICS 2019. Springer, Cham, pp 404\u2013426 (2019)","DOI":"10.1007\/978-3-030-29959-0_20"},{"key":"630_CR33","doi-asserted-by":"publisher","first-page":"14836","DOI":"10.1109\/ACCESS.2021.3052578","volume":"9","author":"J Zhang","year":"2021","unstructured":"Zhang, J., et al.: Formal analysis of QUIC handshake protocol using symbolic model checking. IEEE Access 9, 14836\u201314848 (2021). https:\/\/doi.org\/10.1109\/ACCESS.2021.3052578","journal-title":"IEEE Access"},{"key":"630_CR34","doi-asserted-by":"crossref","unstructured":"Fischlin, M., G\u00fcnther, F., Janson, C.: Robust channels: handling unreliable networks in the record layers of QUIC and DTLS 1.3. Cryptology ePrint Archive, Report 2020\/718. https:\/\/ia.cr\/2020\/718. 2020","DOI":"10.1007\/978-3-030-39903-0_300567"},{"key":"630_CR35","doi-asserted-by":"publisher","unstructured":"Delignat-Lavaud A., et al.: A security model and fully verified implementation for the IETF QUIC record layer. In: 2021 IEEE Symposium on Security and Privacy (SP), pp. 1162\u20131178 (2021). https:\/\/doi.org\/10.1109\/SP40001.2021.00039","DOI":"10.1109\/SP40001.2021.00039"},{"issue":"4","key":"630_CR36","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/s00145-021-09384-1","volume":"34","author":"B Dowling","year":"2021","unstructured":"Dowling, B., et al.: A cryptographic analysis of the TLS 1.3 handshake protocol. J. Cryptol. 34(4), 37 (2021). https:\/\/doi.org\/10.1007\/s00145-021-09384-1","journal-title":"J. Cryptol."},{"key":"630_CR37","unstructured":"Maddux, J.: When TLS hacks you. In: Black Hat (2020)"},{"key":"630_CR38","doi-asserted-by":"publisher","unstructured":"Kampourakis, V., et al.: Revisiting man-inthe- middle attacks against HTTPS. In: Network Security 2022.3 (2022), null. https:\/\/doi.org\/10.12968\/S1353-4858(22)70028-1","DOI":"10.12968\/S1353-4858(22)70028-1"},{"key":"630_CR39","doi-asserted-by":"crossref","unstructured":"Bleichenbacher, D.: Chosen ciphertext attacks against protocols based on the RSA encryption standard PKCS #1. In: Hugo, K., (ed.), Advances in Cryptology\u2014CRYPTO \u201998. Springer, Berlin, pp. 1\u201312, (1998)","DOI":"10.1007\/BFb0055716"},{"key":"630_CR40","doi-asserted-by":"publisher","unstructured":"Jager, T., Schwenk, J\u00f6rg, S., Juraj: On the Security of TLS 1.3 and QUIC against Weaknesses in PKCS#1 v1.5 Encryption. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security. CCS \u201915. Association for Computing Machinery, Denver, pp. 1185\u20131196, (2015). https:\/\/doi.org\/10.1145\/2810103.2813657","DOI":"10.1145\/2810103.2813657"},{"key":"630_CR41","unstructured":"Elaine Barker (NIST): Recommendation for Key Management: Part 1\u2014General\/SP 800-57 Part1 Rev. 5. Visited on 2022-03-29. https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-57-part-1\/rev-5\/final"},{"key":"630_CR42","unstructured":"Aviram, N. et al.: DROWN: breaking TLS using SSLv2\u201d. In: 25th USENIX Security Symposium, USENIX Security 16, Austin, TX, USA, August 10\u201312, 2016. USENIX Association, pp. 689\u2013706 (2016). https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/aviram"},{"key":"630_CR43","doi-asserted-by":"publisher","unstructured":"Cremers, C., et al.: Automated Analysis and Verification of TLS 1.3: 0-RTT, resumption and delayed authentication. In: IEEE Symposium on Security and Privacy, SP 2016, San Jose, CA, USA, May 22\u201326, 2016. IEEE Computer Society, pp. 470\u2013485 (2016). https:\/\/doi.org\/10.1109\/SP.2016.35","DOI":"10.1109\/SP.2016.35"},{"issue":"5","key":"630_CR44","doi-asserted-by":"publisher","first-page":"6483","DOI":"10.3233\/JIFS-179729","volume":"38","author":"B Arunkumar","year":"2020","unstructured":"Arunkumar, B., Kousalya, G.: Nonce reuse\/misuse resistance authentication encryption schemes for modern TLS cipher suites and QUIC based web servers. J. Intell. Fuzzy Syst. 38(5), 6483\u20136493 (2020). https:\/\/doi.org\/10.3233\/JIFS-179729","journal-title":"J. Intell. Fuzzy Syst."},{"key":"630_CR45","unstructured":"Benjamin, D., Wood, C.A.: Importing external PSKs for TLS. Internet-Draft draft-ietf-tlsexternal-psk-importer-07. Work in Progress. Internet Engineering Task Force (2022). https:\/\/www.ietf.org\/id\/draft-ietf-tls-external-psk-importer-07.html"},{"issue":"3","key":"630_CR46","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1007\/s00145-021-09387-y","volume":"34","author":"N Drucker","year":"2021","unstructured":"Drucker, N., Gueron, S.: Selfie: reflections on TLS 1.3 with PSK. J. Cryptol. 34(3), 27 (2021). https:\/\/doi.org\/10.1007\/s00145-021-09387-y","journal-title":"J. Cryptol."},{"key":"630_CR47","doi-asserted-by":"publisher","unstructured":"Saverimoutou, A., Mathieu, B., Vaton, S.: Which secure transport protocol for a reliable HTTP\/2-based web service: TLS or QUIC? In: 2017 IEEE Symposium on Computers and Communications (ISCC), pp. 879\u2013884 (2017). https:\/\/doi.org\/10.1109\/ISCC.2017.8024637","DOI":"10.1109\/ISCC.2017.8024637"},{"key":"630_CR48","doi-asserted-by":"publisher","unstructured":"Fischlin, M., G\u00fcnther, F.: Replay attacks on zero round-trip time: The case of the TLS 1.3 handshake candidates. In: 2017 IEEE European Symposium on Security and Privacy (EuroS P), pp. 60\u201375 (2017). https:\/\/doi.org\/10.1109\/EuroSP.2017.18","DOI":"10.1109\/EuroSP.2017.18"},{"key":"630_CR49","doi-asserted-by":"publisher","unstructured":"Cao, X., Zhao, S., Zhang, Y.: 0-RTT attack and defense of QUIC protocol. In: 2019 IEEE Globecom Workshops (GC Wkshps), pp. 1\u20136 (2019). https:\/\/doi.org\/10.1109\/GCWkshps45667.2019.9024637","DOI":"10.1109\/GCWkshps45667.2019.9024637"},{"key":"630_CR50","doi-asserted-by":"publisher","unstructured":"Lee, S., Shin, Y., Hur, J.: Return of version downgrade attack in the Era of TLS 1.3. In: Association for Computing Machinery, New York, pp. 157\u2013168 (2020). https:\/\/doi.org\/10.1145\/3386367.3431310","DOI":"10.1145\/3386367.3431310"},{"key":"630_CR51","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/978-3-030-41702-4_11","volume-title":"Information Security Theory and Practice","author":"E Gagliardi","year":"2020","unstructured":"Gagliardi, E., Levillain, O.: Analysis of QUIC session establishment and its implementations. In: Laurent, M., Giannetsos, T. (eds.) Information Security Theory and Practice, pp. 169\u2013184. Springer, Cham (2020)"},{"key":"630_CR52","doi-asserted-by":"publisher","unstructured":"Nawrocki, M. et al.: QUICsand: quantifying QUIC reconnaissance scans and DoS flooding events. In: Proceedings of the 21st ACM Internet Measurement Conference. Association for Computing Machinery, New York, pp. 283\u2013291 (2021). https:\/\/doi.org\/10.1145\/3487552.3487840","DOI":"10.1145\/3487552.3487840"},{"key":"630_CR53","unstructured":"caida: UCSD Network Telescope. Visited on 2022-02-15. https:\/\/www.caida.org\/projects\/network_telescope\/"},{"key":"630_CR54","doi-asserted-by":"publisher","unstructured":"McMillan, K.L., Zuck, L.D.: Formal specification and testing of QUIC. In: Proceedings of the ACM Special Interest Group on Data Communication. SIGCOMM\u201919. Association for Computing Machinery, Beijing, pp. 227\u2013240 (2019). https:\/\/doi.org\/10.1145\/3341302.3342087","DOI":"10.1145\/3341302.3342087"},{"key":"630_CR55","doi-asserted-by":"publisher","unstructured":"Reen, G.S., Rossow, C.: DPIFuzz: a differential fuzzing framework to detect DPI elusion strategies for QUIC. In: Annual Computer Security Applications Conference. ACSAC\u201920. Association for Computing Machinery, Austin, pp. 332\u2013344 (2020). https:\/\/doi.org\/10.1145\/3427228.3427662","DOI":"10.1145\/3427228.3427662"},{"key":"630_CR56","unstructured":"quant: A QUIC implementation written in C. Visited on 2022-02-15. https:\/\/github.com\/NTAP\/quant"},{"key":"630_CR57","doi-asserted-by":"publisher","first-page":"1630223:1","DOI":"10.1155\/2021\/1630223","volume":"2021","author":"J Zhang","year":"2021","unstructured":"Zhang, J., et al.: A systematic approach to formal analysis of QUIC handshake protocol using symbolic model checking. Secur. Commun. Netw. 2021, 1630223:1-1630223:12 (2021). https:\/\/doi.org\/10.1155\/2021\/1630223","journal-title":"Secur. Commun. Netw."},{"key":"630_CR58","doi-asserted-by":"publisher","unstructured":"Thimmaraju, K., Scheuermann, B.: Count Me If You Can: enumerating QUIC servers behind load balancers. In: Conference on Networked Systems 2021 (NetSys 2021), vol. 80, Electronic Communications of the EASST (2021). https:\/\/doi.org\/10.14279\/tuj.eceasst.80.1172","DOI":"10.14279\/tuj.eceasst.80.1172"},{"key":"630_CR59","unstructured":"Gbur, K.Y., Tschorsch, F.: A QUIC(K) way through your firewall? In: CoRR abs\/2107.05939 (2021). arXiv: 2107.05939"},{"key":"630_CR60","doi-asserted-by":"crossref","unstructured":"Tong, V., et al.: A novel QUIC traffic classifier based on convolutional neural networks. In: 2018 IEEE Global Communications Conference (GLOBECOM). IEEE, pp. 1\u20136 (2018)","DOI":"10.1109\/GLOCOM.2018.8647128"},{"key":"630_CR61","doi-asserted-by":"crossref","unstructured":"Arfaoui, G., et al.: The privacy of the TLS 1.3 protocol. Cryptology ePrint Archive, Report 2019\/749. https:\/\/ia.cr\/2019\/749 (2019)","DOI":"10.2478\/popets-2019-0065"},{"key":"630_CR62","unstructured":"Govil, Y., Wang, L., Rexford, J.: MIMIQ: Masking IPs with migration in QUIC. In: 10th USENIX Workshop on Free and Open Communications on the Internet (FOCI 20). USENIX Association (2020)"},{"key":"630_CR63","unstructured":"mininet: mininet. Visited on 2022-02-15. http:\/\/mininet.org\/"},{"key":"630_CR64","doi-asserted-by":"publisher","first-page":"108538","DOI":"10.1016\/j.comnet.2021.108538","volume":"200","author":"P Zhan","year":"2021","unstructured":"Zhan, P., Wang, L., Tang, Y.: Website fingerprinting on early QUIC traffic. Comput. Netw. 200, 108538 (2021). https:\/\/doi.org\/10.1016\/j.comnet.2021.108538","journal-title":"Comput. Netw."},{"key":"630_CR65","unstructured":"Barman L., et al.: This is not the padding you are looking for! On the ineffectiveness of QUIC PADDING against website fingerprinting (2022). arXiv: 2203.07806"},{"key":"630_CR66","unstructured":"Near-path NAT for IP Privacy. Last visited 13\/04\/2022. https:\/\/github.com\/bslassey\/ip- blindness\/blob\/master\/near_path_nat.md"},{"key":"630_CR67","unstructured":"Multiplexed Application Substrate over QUIC Encryption (masque). Last visited 13\/04\/2022. https:\/\/datatracker.ietf.org\/wg\/masque\/about\/"},{"key":"630_CR68","unstructured":"W3Techs: Usage statistics of web servers. Last visited 29\/04\/2022. https:\/\/w3techs.com\/technologies\/overview\/web_server"},{"key":"630_CR69","unstructured":"Caddy: GitHub | HTTP\/3 seems to stop working after any kind of reload. Visited on 2022-03- 22. https:\/\/github.com\/caddyserver\/caddy\/issues\/4348"},{"key":"630_CR70","unstructured":"W3Techs: Usage statistics of QUIC for websites. Visited on 2022-03-22. https:\/\/w3techs.com\/technologies\/details\/ce-quic"},{"issue":"3","key":"630_CR71","doi-asserted-by":"publisher","first-page":"214","DOI":"10.1016\/S0167-4048(03)00310-9","volume":"22","author":"S Kamara","year":"2003","unstructured":"Kamara, S., et al.: Analysis of vulnerabilities in Internet firewalls. Comput Secur 22(3), 214\u2013232 (2003). https:\/\/doi.org\/10.1016\/S0167-4048(03)00310-9","journal-title":"Comput Secur"},{"key":"630_CR72","doi-asserted-by":"publisher","unstructured":"G\u00fcnther, F., et al.: 0-RTT key exchange with full forward secrecy. In: Jean-S\u00e9bastien C., Jesper B.N. (eds.), Advances in Cryptology\u2014EUROCRYPT 2017\u201436th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Paris, France, April 30\u2013May 4, 2017, Proceedings, Part III, vol. 10212. Lecture Notes in Computer Science, pp. 519\u2013548 (2017). https:\/\/doi.org\/10.1007\/978-3-319-56617-7_18","DOI":"10.1007\/978-3-319-56617-7_18"},{"key":"630_CR73","doi-asserted-by":"publisher","unstructured":"Dallmeier, F., et al.: Forward-Secure 0-RTT Goes Live: Implementation and performance analysis in QUIC. In: Stephan, K., Haya, S., Serge, V., (eds.), Cryptology and Network Security\u201419th International Conference, CANS 2020, Vienna, Austria, December 14\u201316, 2020, Proceedings, vol. 12579. Lecture Notes in Computer Science. Springer, pp. 211\u2013231 (2020). https:\/\/doi.org\/10.1007\/978-3-030-65411-5_11","DOI":"10.1007\/978-3-030-65411-5_11"},{"key":"630_CR74","unstructured":"draft-aboba-avtcore-quic-multiplexing-04: QUIC Multiplexing. Visited on 2022-05-19. https:\/\/datatracker.ietf.org\/doc\/draft-abobaavtcore-quic-multiplexing\/04\/"},{"key":"630_CR75","unstructured":"draft-engelbart-rtp-over-quic-03: RTP over QUIC. Visited on 2022-05-19. https:\/\/datatracker.ietf.org\/doc\/draft-engelbart-rtp-over-quic\/"},{"key":"630_CR76","doi-asserted-by":"publisher","unstructured":"Kambourakis, G., Karopoulos, G.: Encrypted DNS: the good, the bad and the moot. Comput. Fraud Secur. (2022). https:\/\/doi.org\/10.12968\/S1361-3723(22)70572-6","DOI":"10.12968\/S1361-3723(22)70572-6"},{"key":"630_CR77","doi-asserted-by":"publisher","unstructured":"Hu, G., Fukuda, K.: An analysis of privacy leakage in DoQ traffic. In: Gareth, T., Hannaneh, B.P., Lars C.W. (eds.), CoNEXTSW \u201921: Proceedings of the CoNEXT Student Workshop, Virtual Event\/Munich, Germany, 7 December 2021. ACM, pp. 7\u20138 (2021). https:\/\/doi.org\/10.1145\/3488658.3493782","DOI":"10.1145\/3488658.3493782"},{"key":"630_CR78","unstructured":"Gil, O.: Web cache deception attack. In: Black Hat USA 2017 (2017)"},{"key":"630_CR79","unstructured":"Web Cache Deception Escalates. In: 31st USENIX Security Symposium (USENIX Security 22). USENIX Association, Boston (2022). https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/mirheidari"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-022-00630-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-022-00630-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-022-00630-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,3,17]],"date-time":"2023-03-17T01:13:38Z","timestamp":1679015618000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-022-00630-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,2]]},"references-count":79,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2023,4]]}},"alternative-id":["630"],"URL":"https:\/\/doi.org\/10.1007\/s10207-022-00630-6","relation":{"has-preprint":[{"id-type":"doi","id":"10.21203\/rs.3.rs-1676730\/v1","asserted-by":"object"}]},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,2]]},"assertion":[{"value":"2 December 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declaration"}},{"value":"The authors declare that they have no conflicts of interest regarding the publication of this study.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants or animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}