HTTP/2 & Quic - Teaching Good Protocols to Do Bad Things
by Catherine (Kate) Pearce & Carl Vincent The meteoric rise of SPDY, HTTP/2, and QUIC has gone largely unremarked upon by most of the security field. QUIC is an application-layer UDP-based protocol that multiplexes connections between endpoints at the application level, rather than the kernel level. HTTP/2 (H2) is a successor to SPDY, and multiplexes different HTTP streams within a single connection. More than 10% of the top 1 Million websites are already using some of these technologies, including much of the 10 highest traffic sites. Whether you multiplex out across connections with QUIC, or multiplex into fewer connections with HTTP/2, the world has changed. We have a strong sensation of Déjà vu with this work and our 2014 BlackHat USA MPTCP research. We find ourselves discussing a similar situation in new protocols with technology stacks evolving faster than ever before, and Network Security is largely unaware of the peril already upon it. This talk briefly introduces QUIC and HTTP/2, covers multiplexing attacks beyond MPTCP, discusses how you can use these techniques over QUIC and within HTTP/2, and discusses how to make sense of and defend against H2/QUIC traffic on your network. We will also demonstrate, and release, some tools with these techniques incorporated.

HTTP Cookie Hijacking in the Wild: Security and Privacy Implications

Beyond the Mcse: Active Directory for the Security Professional

HTTP/3 - HTTP over QUIC is the next generation by Daniel Stenberg

What is DNS? (and how it makes the Internet work)

OSI and TCP IP Models - Best Explanation

Breaking FIDO: Are Exploits in There?

Exploiting Network Printers

QUIC 101

Side-Channel Attacks on Everyday Applications

Trump Ruins NBA Finals Vibes, Crashes Out on Meet the Press After CA Election Lies: A Closer Look

Game of Chromes: Owning the Web with Zombie Chrome Extensions

Demystifying the Secure Enclave Processor

The Mind Behind Linux | Linus Torvalds | TED

Harvard Professor Explains The Rules of Writing — Steven Pinker

QUIC: Replacing TCP for the Web

Networking For Hackers! (Common Network Protocols)

AMSI: How Windows 10 Plans to Stop Script-Based Attacks and How Well It Does It

How HTTP/2 Works, Performance, Pros & Cons and More

The Linux Kernel Hidden Inside Windows 10

