On the reduction of authoritative DNS cache timeouts: detection and implications for user privacy

Date

2021

Director

Publisher

Elsevier
Acceso abierto / Sarbide irekia
Artículo / Artikulua
Versión publicada / Argitaratu den bertsioa

Project identifier

  • AEI/Plan Estatal de Investigación Científica y Técnica y de Innovación 2017-2020/PID2019-104451RB-C22/ES/ recolecta
Impacto
No disponible en Scopus

Abstract

The domain name system (DNS) is an Internet network service that is used by hosts to resolve IP addresses from symbolic names. This basic service has been attacked and abused many times, as it is one of the oldest and most vulnerable services on the Internet. Some DNS resolvers conduct DNS manipulation, in which authoritative DNS responses are modified. This DNS manipulation is sometimes used for legitimate reasons (e.g., parental control) and other times is used to support malicious activities, such as DNS poisoning or data collection. Between these DNS manipulation activities, some Internet service providers (ISPs) are changing the DNS cache timeout of the DNS responses with which their DNS resolvers responded to obtain additional data about their subscribers. These data can be a detailed web browsing profile of the user. This approach does not require a large investment and can yield huge benefits if the information is used or sold. Therefore, user privacy is disputed. We conducted a study in which we analyse how ISPs use this DNS manipulation, propose a method for identifying this DNS manipulation by the end-user and determine the amount of information an ISP can collect by using it. We also developed a public web tool, for which the source code is available, that can help Internet users determine whether their privacy is being compromised by their ISP via the exploitation of DNS cache timeouts. This service can facilitate the collection of data on how many people are victims of this abuse and which ISPs around the world are utilizing this technique.

Description

Keywords

DNS cache, DNS manipulation, User privacy

Department

Ingeniaritza Elektrikoa, Elektronikoaren eta Telekomunikazio Ingeniaritzaren / Institute of Smart Cities - ISC / Ingeniería Eléctrica, Electrónica y de Comunicación

Faculty/School

Degree

Doctorate program

item.page.cita

item.page.rights

© 2020 The Author(s). This is an open access article under the CC BY license

Licencia

Los documentos de Academica-e están protegidos por derechos de autor con todos los derechos reservados, a no ser que se indique lo contrario.