[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82713-en":3,"doc-seo-82713-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82713,4810365810221,"Aurora","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","A Binary and System Integrated Analysis Approach for Securing the QUIC Protocol","Quick UDP Internet Connections (QUIC) is widely used to provide secure transport for Internet of Things (IoT) firmware and applications, yet existing evaluations mainly analyze captured network traffic while leaving binary-level presence and activation of standardized defences uncertain. This work proposes BSISA, combining compiled-binary analysis of a QUIC server with system-level analysis of captured traffic. Experiments on four production servers under six attack scenarios show the integrated setup best detects threats, extracts defence functions, and reveals declared-but-silent defences not observable from network capture alone.","A Binary and System Integrated Analysis Approach for Securing the QUIC Protocol  \nMaitha Alshaali 1,2 , Wanqing Tu 1 , Gaofei Huang3 , Mthandazo Ndhlovu2  \n1Durham University, Durham, United Kingdom  \n2Technology Innovation Institute, Abu Dhabi, United Arab Emirates  \n3 Guangzhou University, Guangzhou, China  \narXiv :2607 .03 149v 1 [ cs .NI] 3 Jul 2026  \nAbstract—The Quick UDP Internet Connections (QUIC) protocol is increasingly used to provide secure transport for Internet of Things (IoT) firmware and applications. Existing security analyses of QUIC focus on the captured network traffic, while binary-level analyses of QUIC implementations remain unexplored, leaving open the question of whether a defence specified by the QUIC standard is both present in the compiled binary and active when the server is under attack. This paper evaluates the Binary and System Integrated Security Analysis (BSISA) approach, in which a binary-level analysis of the compiled QUIC server is combined with a system-level analysis of the captured network traffic, on four production QUIC server implementations under six attack scenarios. Across 24 cells, the combined classifier configuration is the only configuration that correctly classifies at least one cell on every attack scenario, achieving 45.8% overall accuracy compared with 37.5% for the binary-level configuration and 25.0% for the system-level configuration. BSISA also identifies the specific defence function in the compiled binary that absorbed each attack, and flags declared-but-silent defences, routines that are present in the compiled binary (Retry-token validation in three of four stacks, anti-amplification in quiche) but never execute during attack, a class of finding that network capture alone cannot produce. In terms of efficiency, picoquicloses legitimate-client availability under slowloris and connectionID exhaustion with failure rates of 72.4% and 73.3% respectively, while the other three implementations hold the failure rate at or below 0.5% . We hope these insights will be informative for QUIC security evaluations in IoT firmware deployments.  \nIndex Terms—QUIC, IoT, intrusion detection, binary analysis, binary and system integrated detection, large language models  \nI. INTRODUCTION  \nThe Internet of Things (IoT) connects constrained devices to cloud services for tasks such as smart-building sensing, vehic  \nular telemetry, and industrial monitoring, where each device must transmit data securely within milliseconds and remain quiet between events [1] . The Quick UDP Internet Connections (QUIC) protocol is designed to secure such communications in a more efficient way as compared to TLS over TCP. This is achieved by integrating the cryptographic handshake into a single round trip and resuming an established connection in zero round trips [2], [3] . QUIC is increasingly adopted as the transport-layer protocol for MQTT in constrained IoT deployments [1], providing secure transport for the delivery of new IoT firmware. We focus on the server side because the device classes that run a QUIC server include industrial IoT  \ngateways, smart-home hubs, on-premise MQTT brokers, and Corresponding author: Wanqing Tu ([wanqing.tu@durham.ac.uk](wanqing.tu@durham.ac.uk)).  \nedge inference nodes, all settings where the deployed binary is the only artefact a defender can inspect. However, recent studies indicate that QUIC does not consistently outperform the traditional TLS-over-TCP stack when evaluated against diverse security threats [4] . Accordingly, this paper exploreshow to strengthen QUIC’s resilience against different threats. QUIC security research has so far focused on system-level techniques, including encrypted client hello [5], stateless Retry token hardening [6], software-defined-network based path security [7], and machine-learning detection of malicious traffic patterns within encrypted streams [8] . Binary analysis has been applied to authentication bypass in firmware binaries [9], ","cbCaihkTu9GvCpYZ","https://ap.wps.com/l/cbCaihkTu9GvCpYZ","pdf",463286,3,1,9,"English","en",105,"# Introduction\n## Motivation and problem gap\n## Related security work\n## Research questions and contributions","[{\"question\":\"What problem does the BSISA approach address in QUIC security evaluation?\",\"answer\":\"It targets the evidence gap between QUIC standard defences and whether they actually exist in the compiled server binary and execute during an active attack.\"},{\"question\":\"How is BSISA constructed from binary and system evidence?\",\"answer\":\"BSISA integrates binary-level investigation of the compiled QUIC server (including protocol-related defences and system-call behavior) with system-level analysis of captured network traffic.\"},{\"question\":\"What key advantage does BSISA provide over network-capture-only analysis?\",\"answer\":\"It can identify specific defence functions that absorb attacks and flag declared-but-silent routines that are present in the binary but never execute during attacks.\"}]",1784182447,23,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"a-binary-and-system-integrated-analysis-approach-for-securing-the-quic-protocol","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/a-binary-and-system-integrated-analysis-approach-for-securing-the-quic-protocol/82713/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-23","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the BSISA approach address in QUIC security evaluation?","Question",{"text":75,"@type":76},"It targets the evidence gap between QUIC standard defences and whether they actually exist in the compiled server binary and execute during an active attack.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How is BSISA constructed from binary and system evidence?",{"text":80,"@type":76},"BSISA integrates binary-level investigation of the compiled QUIC server (including protocol-related defences and system-call behavior) with system-level analysis of captured network traffic.",{"name":82,"@type":73,"acceptedAnswer":83},"What key advantage does BSISA provide over network-capture-only analysis?",{"text":84,"@type":76},"It can identify specific defence functions that absorb attacks and flag declared-but-silent routines that are present in the binary but never execute during attacks.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]