Oblivious DNS over HTTPS (ODoH): A Practical Privacy Enhancement to DNS

Author:

Singanamalla Sudheesh1,Chunhapanya Suphanat2,Hoyland Jonathan2,Vavruša Marek2,Verma Tanya2,Wu Peter2,Fayed Marwan2,Heimerl Kurtis3,Sullivan Nick2,Wood Christopher2

Affiliation:

1. University of Washington , and Cloudflare Inc. Sudheesh was with Cloudflare Inc. while doing this work.

2. Cloudflare Inc.

3. University of Washington

Abstract

Abstract The Internet’s Domain Name System (DNS) responds to client hostname queries with corresponding IP addresses and records. Traditional DNS is unencrypted and leaks user information to on-lookers. Recent efforts to secure DNS using DNS over TLS (DoT) and DNS over HTTPS (DoH) have been gaining traction, ostensibly protecting DNS messages from third parties. However, the small number of available public large-scale DoT and DoH resolvers has reinforced DNS privacy concerns, specifically that DNS operators could use query contents and client IP addresses to link activities with identities. Oblivious DNS over HTTPS (ODoH) safeguards against these problems. In this paper we implement and deploy interoperable instantiations of the protocol, construct a corresponding formal model and analysis, and evaluate the protocols’ performance with wide-scale measurements. Results suggest that ODoH is a practical privacy-enhancing replacement for DNS.

Publisher

Walter de Gruyter GmbH

Subject

General Medicine

Reference84 articles.

1. [1] ODoH Analysis Tamarin Model. https://github.com/cloudflare/odoh-analysis.

2. [2] ODoH Artifacts. https://github.com/sudheesh001/ODoH-Artifacts.

3. [3] N Aifardan, D Bernstein, K Paterson, B Poettering, and J Schuldt. On the security of RC4 in TLS and WPA. In USENIX Security, 2013.

4. [4] Michael Backes, Aniket Kate, Praveen Manoharan, Sebastian Meiser, and Esfandiar Mohammadi. AnoA: A Framework for Analyzing Anonymous Communication Protocols. In 2013 IEEE 26th Computer Security Foundations Symposium, pages 163–178, 2013.

5. [5] Kenji Baheux. Chromium blog: A safer and more private browsing experience with secure DNS. https://blog.chromium.org/2020/05/a-safer-and-more-private-browsing-DoH.html, 05 2020. (Accessed on 09/15/2020).

Cited by 15 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. VPIR: an efficient verifiable private information retrieval scheme resisting malicious cloud server;Telecommunication Systems;2024-05-28

2. Tracking and Blocking Adware using DNS Sinkholing Algorithm;2024 16th International Conference on Computer and Automation Engineering (ICCAE);2024-03-14

3. μODNS: A distributed approach to DNS anonymization with collusion resistance;Computer Networks;2023-12

4. Where on Earth is the Spatial Name System?;Proceedings of the 22nd ACM Workshop on Hot Topics in Networks;2023-11-28

5. Demo: PDNS: A Fully Privacy-Preserving DNS;Proceedings of the ACM SIGCOMM 2023 Conference;2023-09

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3