International Journal For Multidisciplinary Research

E-ISSN: 2582-2160     Impact Factor: 9.24

A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal

Call for Paper Volume 8, Issue 2 (March-April 2026) Submit your research before last 3 days of April to publish your research paper in the issue of March-April.

QUICsand: Exploiting State-Table Saturation and Connection ID Ambiguity for Session Hijacking in QUIC-Enabled Architectures

Author(s) Dr. Rohitkumar Gautam, Dr. Shifa Cyclewala
Country India
Abstract The QUIC transport protocol introduces a paradigm shift in session persistence through the use of Connection Identifiers (CIDs), decoupling connections from the traditional network 4-tuple. While this enables seamless connection migration, it introduces a critical dependency on the state-tracking capabilities of intermediate middleboxes and Load Balancers (LBs). This paper introduces QUICsand, a novel attack vector that leverages CID-induced state exhaustion. By "drowning" the LB's mapping table with high-entropy, orphaned CIDs, an attacker can force the infrastructure into an "Ambiguity State." In this state, the LB reverts to deterministic hashing, allowing an attacker to predict and collide with legitimate user traffic. We present a Proof-of-Concept (PoC) demonstrating a session takeover success rate of $12.2% in simulated high-traffic environments.
Keywords quic, quicsand, quicprotocol
Field Computer > Data / Information
Published In Volume 7, Issue 6, November-December 2025
Published On 2025-12-21
DOI https://doi.org/10.36948/ijfmr.2025.v07i06.64159

Share this