Assessing the Privacy Benefits of Domain Name Encryption

11/01/2019
by   Nguyen Phong Hoang, et al.
0

As Internet users have become more savvy about the potential for their Internet communication to be observed, the use of network traffic encryption technologies (e.g., HTTPS/TLS) is on the rise. However, even when encryption is enabled, users leak information about the domains they visit via their DNS queries and via the Server Name Indication (SNI) extension of TLS. Two proposals to ameliorate this issue are DNS over HTTPS/TLS (DoH/DoT) and Encrypted SNI (ESNI). In this paper we aim to assess the privacy benefits of these proposals by considering the relationship between hostnames and IP addresses, the latter of which are still exposed. We perform DNS queries from nine vantage points around the globe to characterize this relationship. We quantify the privacy gain due to ESNI for different hosting and CDN providers using two different metrics, the k-anonymity degree due to co-hosting and the dynamics of IP address changes. We find that 20 not gain any privacy benefit since they have a one-to-one mapping between their hostname and IP address. Our results show that 30 privacy benefit with a k value greater than 100, meaning that an adversary can correctly guess these domains with a probability less than 1 visitors will gain a high privacy level are far less popular, while visitors of popular sites will gain much less. Analyzing the dynamics of IP addresses of long-lived domains, we find that only 7.7 addresses on a daily basis. We conclude by discussing potential approaches for website owners and hosting/CDN providers for maximizing the privacy benefits of ESNI.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/16/2021

Domain Name Encryption Is Not Enough: Privacy Leakage via IP-based Website Fingerprinting

Domain name encryptions (DoTH and ESNI) have been proposed to improve se...
research
11/06/2019

Polymorphic Encryption and Pseudonymisation of IP Network Flows

We describe a system, PEP3, for storage and retrieval of IP flow informa...
research
01/03/2022

A Survey on DNS Encryption: Current Development, Malware Misuse, and Inference Techniques

The domain name system (DNS) that maps alphabetic names to numeric Inter...
research
02/01/2022

Measuring the Accessibility of Domain Name Encryption and Its Impact on Internet Filtering

Most online communications rely on DNS to map domain names to their host...
research
07/08/2023

Internet Localization of Multi-Party Relay Users: Inherent Friction Between Internet Services and User Privacy

Internet privacy is increasingly important on the modern Internet. Users...
research
04/08/2022

Measurement and characterization of DNS over HTTPS traffic

Domain name system communication may provide sensitive information on us...
research
04/20/2022

SiamHAN: IPv6 Address Correlation Attacks on TLS Encrypted Traffic via Siamese Heterogeneous Graph Attention Network

Unlike IPv4 addresses, which are typically masked by a NAT, IPv6 address...

Please sign up or login with your details

Forgot password? Click here to reset