K-resolver: Towards Decentralizing Encrypted DNS Resolution

01/24/2020
by   Nguyen Phong Hoang, et al.
0

Centralized DNS over HTTP/TLS (DoH/DoT) resolution, which has started being deployed by major hosting providers and web browsers, has sparked controversy among Internet activists and privacy advocates due to several privacy concerns. This design decision causes the trace of all DNS resolutions to be exposed to a third-party resolver, different than the one specified by the user's access network. In this work we propose K-resolver, a DNS resolution mechanism that disperses DNS queries across multiple DoH resolvers, reducing the amount of information about a user's browsing activity exposed to each individual resolver. As a result, none of the resolvers can learn a user's entire web browsing history. We have implemented a prototype of our approach for Mozilla Firefox, and used it to evaluate the performance of web page load time compared to the default centralized DoH approach. While our K-resolver mechanism has some effect on DNS resolution time and web page load time, we show that this is mainly due to the geographical location of the selected DoH servers. When more well-provisioned anycast servers are available, our approach incurs negligible overhead while improving user privacy.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/20/2023

On Cross-Layer Interactions of QUIC, Encrypted DNS and HTTP/3: Design, Evaluation and Dataset

Every Web session involves a DNS resolution. While, in the last decade, ...
research
11/02/2020

There's No Trick, Its Just a Simple Trick: A Web-Compat and Privacy Improving Approach to Third-party Web Storage

While much current web privacy research focuses on browser fingerprintin...
research
02/22/2018

Investigating the Evolvability of Web Page Load Time

Client-side Javascript execution environments (browsers) allow anonymous...
research
09/13/2019

An Empirical Study of the Cost of DNS-over-HTTPS

DNS is a vital component for almost every networked application. Origina...
research
08/13/2019

ConfigTron: Tackling network diversity with heterogeneous configurations

The web serving protocol stack is constantly changing and evolving to ta...
research
02/26/2023

Reclaiming Privacy and Performance over Centralized DNS

The Domain Name System (DNS) is both a key determinant of users' quality...
research
07/18/2019

Analyzing the Costs (and Benefits) of DNS, DoT, and DoH for the Modern Web

Essentially all Internet communication relies on the Domain Name System ...

Please sign up or login with your details

Forgot password? Click here to reset