Encrypted DNS -> Privacy? A Traffic Analysis Perspective
Sandra Deepthy Siby, Marc Juarez, Claudia Díaz, Narseo Vallina-Rodriguez, Carmela Troncoso
Abstract
Virtually every connection to an Internet service is preceded by a DNS lookup which is performed without any traffic-level protection, thus enabling manipulation, redirection, surveillance, and censorship. To address these issues, large organizations such as Google and Cloudflare are deploying recently standardized protocols that encrypt DNS traffic between end users and recursive resolvers such as DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH). In this paper, we examine whether encrypting DNS traffic can protect users from traffic analysis-based monitoring and censoring. We propose a novel feature set to perform the attacks, as those used to attack HTTPS or Tor traffic are not suitable for DNS' characteristics. We show that traffic analysis enables the identification of domains with high accuracy in closed and open world settings, using 124 times less data than attacks on HTTPS flows. We find that factors such as location, resolver, platform, or client do mitigate the attacks performance but they are far from completely stopping them. Our results indicate that DNS-based censorship is still possible on encrypted DNS traffic. In fact, we demonstrate that the standardized padding schemes are not effective. Yet, Tor -- which does not effectively mitigate traffic analysis attacks on web traffic -- is a good defense against DoH traffic analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5cfa1ca2-fe1b-43b6-a48f-feff0d5c4e80Cited by top-tier papers21
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- Brain-on-Switch: Towards Advanced Intelligent Network Data Plane via NN-Driven Traffic Analysis at Line-SpeedJinzhu Yan, Haotian Xu, Zhuotao Liu, Qi Li et al.NSDI 2024 · 60 citations
- Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNSPhilipp Jeitner, Haya SchulmannUSENIX Security 2021 · 32 citations
- Point Cloud Analysis for ML-Based Malicious Traffic Detection: Reducing Majorities of False Positive AlarmsChuanpu Fu, Qi Li, Ke Xu, Jianping WuCCS 2023 · 30 citations
- Understanding the Impact of Encrypted DNS on Internet CensorshipLin Jin, Shuai Hao, Haining Wang, Chase CottonWWW 2021 · 29 citations
Builds on9
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- Website Fingerprinting at Internet ScaleAndriy Panchenko, Fabian Lanze, Jan Pennekamp, Thomas Engel et al.NDSS 2016 · 625 citations
- k-fingerprinting: A Robust Scalable Website Fingerprinting TechniqueJamie Hayes, George DanezisUSENIX Security 2016 · 474 citations
- Automated Website Fingerprinting through Deep LearningVera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem et al.NDSS 2018 · 399 citations
- Global Measurement of DNS ManipulationPaul Pearce, Ben Jones, Frank Li, Roya Ensafi et al.USENIX Security 2017 · 163 citations
Related papers
- Comparing the Effects of DNS, DoT, and DoH on Web PerformanceAustin Hounsel, Kevin Borgolte, Paul Schmitt, Jordan Holland et al.WWW 2020 · 59 citations
- A Worldwide View on the Reachability of Encrypted DNS ServicesRuixuan Li, Baojun Liu, Chaoyi Lu, Haixin Duan et al.WWW 2024 · 12 citations
- The Effect of DNS on Tor's AnonymityBenjamin Greschbach, Tobias Pulls, Laura M. Roberts, Philipp Winter et al.NDSS 2017 · 51 citations
- Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-LayerNiklas Niere, Felix Lange, Robert Merget, Juraj SomorovskyS&P 2025
- ditto: WAN Traffic Obfuscation at Line RateRoland Meier, Vincent Lenders, Laurent VanbeverNDSS 2022
