arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

关于量子后密码学在TLS中的安全影响:握手耗尽与入侵检测系统性能下降

On the Security Implications of PQC in TLS: Handshake Exhaustion and IDS Degradation

Lin-Fa Lee, Yi-Yu Chang, Chia-Mu Yu, Kuo-Hui Yeh

arXiv 2607.12504首次发表:更新:

AI 中文总结

研究PQC集成到TLS 1.3中的安全影响,通过实验发现其放大握手耗尽攻击,导致IDS性能下降。贡献包括量化分析检测盲点原因、发布混合流量数据集及开源代码和脚本,以助力开发PQC感知入侵检测系统。

AI 中文摘要

量子后密码学(PQC)正越来越多地集成到TLS 1.3中,以增强抵御量子攻击的能力。然而,PQC原语在握手阶段引入的额外计算和通信开销,可能会放大TLS握手耗尽攻击的影响,导致更严重的分布式拒绝服务(DDoS)威胁。本研究建立了一个由一个启用PQC的TLS服务器和十个攻击节点组成的实证测试平台,生成了超过16.5GB的混合流量数据,包括合法浏览行为和高强度握手耗尽攻击。实验结果表明,PQC-TLS可将服务器上持续高CPU利用率的时间延长多达88倍,显著增强此类攻击的有效性。此外,评估了基于深度学习的先进入侵检测系统(IDS),发现在PQC流量条件下攻击检测性能大幅下降。特别是,exosphere的召回率仅约为50%,而HyperVision的AU-ROC降至接近随机水平(0.49),揭示了现有IDS在PQC环境中运行时的关键检测盲点。这项工作的主要贡献有三个方面:(1)系统地量化和分析了PQC设置中IDS检测盲点的根本原因;(2)公开发布了一个全面的PQC-DDoS混合流量数据集,包括精确的攻击时间戳和服务器端资源监控数据;(3)开源了所有实验代码和AWS部署脚本,实现了一个完全可重现的基于云的测试环境。这些资源旨在支持学术界和工业界开发下一代PQC感知入侵检测系统。

英文摘要

Post-Quantum Cryptography (PQC) is increasingly being integrated into TLS 1.3 to enhance resilience against quantum-enabled attacks. However, the additional computational and communication overhead introduced by PQC primitives during the handshake phase may also amplify the impact of TLS handshake exhaustion attacks, leading to more severe Distributed Denial-of-Service (DDoS) threats. In this study, we establish an empirical testbed consisting of one PQC-enabled TLS server and ten attacking nodes, generating over 16.5 GB of mixed traffic data that includes both legitimate browsing behavior and high-intensity handshake exhaustion attacks. Experimental results show that PQC-TLS can prolong periods of sustained high CPU utilization on the server by up to 88 times, significantly amplifying the effectiveness of such attacks. Furthermore, we evaluate state-of-the-art deep learning-based Intrusion Detection Systems (IDS) and observe a substantial decline in attack detection performance under PQC traffic conditions. In particular, exosphere achieves only around 50% recall, while HyperVision's AU-ROC degrades to near-random levels (0.49), revealing critical detection blind spots in existing IDS when operating in PQC environments. The main contributions of this work are threefold: (1) we systematically quantify and analyze the root causes of IDS detection blind spots in PQC settings; (2) we publicly release a comprehensive PQC-DDoS hybrid traffic dataset, including precise attack timestamps and server-side resource monitoring data; and (3) we open-source all experimental code and AWS deployment scripts, enabling a fully reproducible cloud-based testing environment. These resources aim to support both academia and industry in developing next-generation PQC-aware intrusion detection systems.

Comments24 pages,4 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑