QUIC-Exfil: Exploiting QUIC's Server Preferred Address Feature to Perform Data Exfiltration Attacks
Thomas Gr\"ubl, Weijie Niu, Jan von der Assen, Burkhard Stiller

TL;DR
This paper demonstrates a novel method to perform covert data exfiltration over QUIC by exploiting the server preferred address feature, which evades current detection mechanisms and firewall defenses.
Contribution
We introduce a new QUIC-based data exfiltration attack leveraging server preferred address, and show it is undetectable by existing anomaly detection classifiers and firewall solutions.
Findings
Existing classifiers fail to detect the exfiltration attack.
Current firewalls do not distinguish malicious QUIC connection migrations.
The attack remains covert under various network scenarios.
Abstract
The QUIC protocol is now widely adopted by major tech companies and accounts for a significant fraction of today's Internet traffic. QUIC's multiplexing capabilities, encrypted headers, dynamic IP address changes, and encrypted parameter negotiations make the protocol not only more efficient, secure, and censorship-resistant, but also practically unmanageable by firewalls. This opens doors for attackers who may exploit certain traits of the QUIC protocol to perform targeted attacks, such as data exfiltration attacks. Whereas existing data exfiltration techniques, such as TLS and DNS-based exfiltration, can be detected on a firewall level, QUIC-based data exfiltration is more difficult to detect, since changes in IP addresses and ports are inherent to the protocol's normal behavior. To show the feasibility of a QUIC-based data exfiltration attack, we introduce a novel method leveraging…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Packet Processing and Optimization · Network Security and Intrusion Detection · Internet Traffic Analysis and Secure E-voting
