Encrypted DNS ⇒ Privacy? A Traffic Analysis Perspective

Sandra Siby, Marc Juarez, Claudia Diaz, Narseo Vallina-Rodriguez, Carmela Troncoso

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Virtually every connection to an Internet service is preceded by a DNS lookup. Lookups are performed without any traffic-level protection, thus enabling manipulation, redirection, surveillance, and censorship. To address these issues, large organizations such as Google and Cloudflare are deploying standardized protocols that encrypt DNS traffic between end users and recursive resolvers: DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH). In this paper, we examine whether encrypting DNS traffic can protect users from traffic analysis-based monitoring and censoring. We propose a novel feature set to perform traffic analysis attacks, as the features used to attack HTTPS or Tor traffic are not suitable for DNS' characteristics. We show that traffic analysis enables the identification of domains with high accuracy in closed and open world settings, using 124 times less data than attacks on HTTPS flows. We also show that DNS-based censorship is still possible on encrypted DNS traffic. We find that factors such as end-user location, recursive resolver, platform, or DNS client do negatively affect the attacks' performance, but they are far from completely stopping them. We demonstrate that the standardized padding schemes are not effective. Yet, Tor 'which does not effectively mitigate traffic analysis attacks on web traffic' is a good defense against DoH traffic analysis.

Original languageEnglish (US)
Title of host publication27th Annual Network and Distributed System Security Symposium, NDSS 2020
PublisherThe Internet Society
ISBN (Electronic)1891562614, 9781891562617
DOIs
StatePublished - 2020
Event27th Annual Network and Distributed System Security Symposium, NDSS 2020 - San Diego, United States
Duration: Feb 23 2020Feb 26 2020

Publication series

Name27th Annual Network and Distributed System Security Symposium, NDSS 2020

Conference

Conference27th Annual Network and Distributed System Security Symposium, NDSS 2020
Country/TerritoryUnited States
CitySan Diego
Period2/23/202/26/20

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Control and Systems Engineering
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'Encrypted DNS ⇒ Privacy? A Traffic Analysis Perspective'. Together they form a unique fingerprint.

Cite this