AI 中文总结
本研究提出一种无需修改连接ID的无状态QUIC负载均衡实现方法,可在数据平面内保障QUIC负载均衡安全,同时缓解负载均衡器完全绕过和0-RTT IP欺骗等攻击。
AI 中文摘要
网络内负载均衡性能优于传统软件负载均衡且成本更低,例如可编程交换机ASIC可使用哈希算法以线速为每个流的初始数据包选择后端服务器。然而,当可用服务器池发生变化时,由于数据平面的内存资源有限且性能要求高,确保后续流数据包映射到同一服务器颇具挑战。随着QUIC传输协议的出现,多项研究表明连接ID(CID)字段可在所有非初始数据包中嵌入服务器标识符,但该方法需要修改服务器端,且违反了QUIC规范中要求CID保持不可链接的规定。本研究展示了无需修改CID即可在数据平面内实现无状态QUIC负载均衡,此外,除客户端初始数据包外的QUIC数据包可绕过负载均衡器,我们还研究并缓解了该场景下针对QUIC的攻击,包括完全绕过负载均衡器和0-RTT IP欺骗。
英文摘要
In-network load balancing outperforms traditional software load balancing while costing less. For instance, programmable switch ASICs can use hashing to select the backend server for the initial packet of each flow at the line rate. However, when the pool of available servers changes, ensuring that the subsequent flow packets are mapped to the same server is challenging due to the data plane's limited memory resources and performance requirements. With the emergence of the QUIC transport protocol, several works show how Connection ID fields (CIDs) can embed the server identifier for all non-initial packets. This approach requires modifications on the server side and violates the QUIC specification, which mandates that CIDs remain unlinkable. In this work, we show that stateless QUIC load balancing can be implemented inside the data plane with no changes to CIDs. Moreover, QUIC packets, except the initial client packet, can bypass the load balancer. We also investigate and mitigate attacks on QUIC in this scenario, including full load balancer bypass and 0-RTT IP spoofing.
Journal ref2026 IEEE 27th International Conference on High Performance Switching and Routing (HPSR)
DOI:10.1109/HPSR68369.2026.11615179