Encrypted DNS --> Privacy? A Traffic Analysis Perspective

06/24/2019
by   Sandra Siby, et al.
0

Virtually every connection to an Internet service is preceded by a DNS lookup. These lookups are performed in the clear without integrity protection, enabling manipulation, redirection, surveillance, and censorship. In parallel with standardization efforts that address these issues, large providers such as Google and Cloudflare are deploying solutions to encrypt lookups, such as DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH). In this paper we examine whether encrypting DoH traffic can protect users from traffic analysis-based monitoring and censoring. We find that performing traffic analysis on DoH traces requires different features than those used to attack HTTPS or Tor traffic. We propose a new feature set tailored to the characteristics of DoH traffic. Our classifiers obtain an F1-score of 0.9 and 0.7 in closed and open world settings, respectively. We show that although factors such as location, resolver, platform, or client affect performance, they are far from completely deterring the attacks. We then study deployed countermeasures and show that, in contrast with web traffic, Tor effectively protects users. Specified defenses, however, still preserve patterns and leave some webs unprotected. Finally, we show that web censorship is still possible by analysing DoH traffic and discuss how to selectively block content with low collateral damage.

READ FULL TEXT
research
04/19/2023

Maybenot: A Framework for Traffic Analysis Defenses

End-to-end encryption is a powerful tool for protecting the privacy of I...
research
04/03/2019

Using Google Analytics to Support Cybersecurity Forensics

Web traffic is a valuable data source, typically used in the marketing s...
research
05/15/2020

Watching the Watchers: Nonce-based Inverse Surveillance to Remotely Detect Monitoring

Internet users and service providers do not often know when traffic is b...
research
06/22/2022

HTTPS Event-Flow Correlation: Improving Situational Awareness in Encrypted Web Traffic

Achieving situational awareness is a challenging process in current HTTP...
research
04/08/2022

Measurement and characterization of DNS over HTTPS traffic

Domain name system communication may provide sensitive information on us...
research
03/15/2022

This is not the padding you are looking for! On the ineffectiveness of QUIC PADDING against website fingerprinting

Website fingerprinting (WF) is a well-know threat to users' web privacy....
research
05/24/2021

Every Byte Matters: Traffic Analysis of Bluetooth Wearable Devices

Wearable devices such as smartwatches, fitness trackers, and blood-press...

Please sign up or login with your details

Forgot password? Click here to reset