...
首页> 外文期刊>Computer communication review >Does Domain Name Encryption Increase Users' Privacy?
【24h】

Does Domain Name Encryption Increase Users' Privacy?

机译:域名加密是否会增加用户的隐私?

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Knowing domain names associated with traffic allows eavesdroppers to profile users without accessing packet payloads. Encrypting domain names transiting the network is, therefore, a key step to increase network confidentiality. Latest efforts include encrypting the TLS Server Name Indication (eSNI extension) and encrypting DNS traffic, with DNS over HTTPS (DoH) representing a prominent proposal. In this paper, we show that an attacker able to observe users' traffic relying on plain-text DNS can uncover the domain names of users relying on eSNI or DoH. By relying on large-scale network traces, we show that simplistic features and off-the-shelf machine learning models are sufficient to achieve surprisingly high precision and recall when recovering encrypted domain names. The triviality of the attack calls for further actions to protect privacy, in particular considering transient scenarios in which only a fraction of users will adopt these new privacy-enhancing technologies.
机译:知道与流量关联的域名允许窃听者在不访问数据包有效载荷的情况下进行配置文件。因此,加密域名转运网络是增加网络机密性的关键步骤。最新努力包括加密TLS服务器名称指示(ESNI扩展)和加密DNS流量,DNS通过HTTPS(DOH)表示突出的提案。在本文中,我们表明攻击者能够观察依赖于纯文本DNS的用户的流量,可以揭示依赖于ESNI或DOH的用户的域名。通过依靠大型网络迹线,我们表明,在恢复加密域名时,我们表明简单的功能和现成的机器学习模型足以实现令人惊讶的高精度和召回。攻击的琐事呼吁进行进一步的行动来保护隐私,特别是考虑到暂行情景,其中只有一小部分用户将采用这些新的隐私增强技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号