Enumerating Privacy Leaks in DNS Data Collected above the Recursive
Enumerating Privacy Leaks in DNS Data Collected above the Recursive
复制标题
枚举递归以上收集的 DNS 数据中的隐私泄漏
DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
J. Heidemann
中科院分区:
文献类型:
--
作者:
Basileal Imana;A. Korolova;J. Heidemann
—As with any information system consisting of data derived from people’s actions, DNS data is vulnerable to privacy risks. In DNS, users make queries through recursive resolvers to authoritative servers. Data collected below (or in) the recursive resolver directly exposes users, so most prior DNS data sharing focuses on queries above the recursive resolver. Data collected above a recursive resolver has largely been seen as posing a minimal privacy risk since recursive resolvers typically aggregate traffic for many users, thereby hiding their identity and mixing their traffic. Although this assumption is widely made, to our knowledge it has not been verified. In this paper we re-examine this assumption for DNS traffic above the recursive resolver. First, we show that two kinds of information appear in query names above the recursive resolver: IP addresses and sensitive domain names, such as those pertaining to health, politics, or personal or lifestyle information. Second, we examine how often these classes of potentially sensitive names appear in Root DNS traffic, using 48 hours of B-Root data from April 2017.
影响因子:
3.2
作者:
Minotti,Giorgio;Sarvazyan,Narine
通讯作者:
Sarvazyan,Narine