论文标题

HTTPS(ODOH)遗忘的DNS:对DNS的实际隐私增强

Oblivious DNS over HTTPS (ODoH): A Practical Privacy Enhancement to DNS

论文作者

Singanamalla, Sudheesh, Chunhapanya, Suphanat, Vavruša, Marek, Verma, Tanya, Wu, Peter, Fayed, Marwan, Heimerl, Kurtis, Sullivan, Nick, Wood, Christopher

论文摘要

域名系统(DNS)是可使用的Internet的基础,响应了带有相应IP地址和记录的主机名的客户查询。传统的DNS也没有加密,并将用户信息泄漏到网络运营商。最近在HTTPS(DOH)上使用DNS(DOT)和DNS确保DNS确保DNS的努力一直在受到关注,表面上可以保护流量并将内容隐藏在旁观者中。但是,对DOT和DOH的批评之一是由少量大规模部署(例如Comcast,Google,Cloudflare)所引起的:DNS解析器可以将查询内容与IP地址形式的客户端身份相关联。 HTTPS(ODOH)保障措施的遗漏DNS避免了此问题。在本文中,我们问使ODOH实用需要什么?我们描述了ODOH,这是一种实用的DNS协议,旨在通过保护客户的内容和身份来解决此问题。我们实施和部署协议,并执行测量,以表明ODOH与DOH和DOT等协议具有可比性的性能,这些协议已获得广泛采用,同时改善了客户的隐私,使ODOH成为使用DNS使用的实用隐私增强。

The Domain Name System (DNS) is the foundation of a human-usable Internet, responding to client queries for host-names with corresponding IP addresses and records. Traditional DNS is also unencrypted, and leaks user information to network operators. Recent efforts to secure DNS using DNS over TLS (DoT) and DNS over HTTPS (DoH) have been gaining traction, ostensibly protecting traffic and hiding content from on-lookers. However, one of the criticisms of DoT and DoH is brought to bear by the small number of large-scale deployments (e.g., Comcast, Google, Cloudflare): DNS resolvers can associate query contents with client identities in the form of IP addresses. Oblivious DNS over HTTPS(ODoH) safeguards against this problem. In this paper we ask what it would take to make ODoH practical? We describe ODoH, a practical DNS protocol aimed at resolving this issue by both protecting the client's content and identity. We implement and deploy the protocol, and perform measurements to show that ODoH has comparable performance to protocols like DoH and DoT which are gaining widespread adoption, while improving client privacy, making ODoH a practical privacy enhancing replacement for the usage of DNS.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源