Hardening HTTP/3 QUIC Header Compression (1090)
Technical Overview
HTTP/3's QPACK header compression (RFC 9204) introduces a dynamic table and static table mechanism that reduces header overhead but expands the attack surface for compression side-channels (e.g., CRIME, BREACH) and resource exhaustion. On bare-metal, where NIC offloads and kernel bypass (XDP, DPDK) are common, the QUIC stack runs in userspace, making traditional kernel hardening insufficient.
This article details a defense-in-depth strategy: (1) QPACK encoder/decoder hardening via maximum dynamic table capacity limits and insertion count thresholds; (2) constant-time Huffman decoding to defeat timing leaks; (3) kernel-level UDP socket buffer tuning and XDP drop rules for malformed frames; (4) eBPF-based telemetry for real-time compression ratio anomaly detection.
Threat Model & Attack Vectors
- Compression Ratio Side-Channels: Attacker-controlled header fields influence dynamic table state, leaking secret tokens via observable packet sizes.
- Dynamic Table Exhaustion: Malicious streams force excessive insertions, causing OOM in userspace QUIC libraries.
- Header Block Decoding DoS: Crafted Huffman codes trigger worst-case decoding paths.
- Stream Multiplexing Abuse: Interleaved HEADERS frames across streams amplify state synchronization overhead.
Mitigations must be applied at the protocol logic layer, the userspace networking library (e.g., quiche, msquic, lsquic), and the host OS network stack.
Kernel & NIC Tuning for QUIC on Bare Metal
Since QUIC runs over UDP, standard TCP tuning (e.g., net.ipv4.tcp_*) does not apply. Critical sysctls:
# Increase UDP receive buffers for high-throughput QUIC
net.core.rmem_max = 16777216
net.core.rmem_default = 4194304
net.ipv4.udp_rmem_min = 8192
# Enable XDP redirect for QUIC port (443) to userspace AF_XDP socket
# (requires loaded XDP program)
# ethtool -X equal 64
Additionally, deploy an XDP program that validates QUIC packet headers (version, connection ID length) before passing to userspace, dropping malformed packets early.
eBPF/XDP kernel filter evaluates TCP/UDP frames directly on server NIC.
Observability & Automated Remediation
Deploy eBPF probes on udp_recvmsg and userspace QUIC library hooks to export:
- Dynamic table size vs. max capacity
- Header block decode latency percentiles
- Compression ratio per stream (uncompressed/compressed bytes)
Alert when compression ratio exceeds 1.5x baseline or decode latency > 2ms. Automated response: scale dynamic table capacity down, enable block_new_entries, or trigger connection drain.