Institutional Privacy Risks in Sharing DNS Data

被引:3
|
作者
Imana, Basileal [1 ]
Korolova, Aleksandra [1 ]
Heidemann, John [2 ]
机构
[1] Univ Southern Calif, Los Angeles, CA 90007 USA
[2] USC, Informat Sci Inst, Los Angeles, CA 90007 USA
关键词
D O I
10.1145/3472305.3472324
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The Domain Name System (DNS) is used in every website visit and e-mail transmission, so privacy is an obvious concern. In DNS, users ask recursive resolvers (or "recursives") to make queries on their behalf. Prior analysis of DNS privacy focused on privacy risks to individual end-users, mainly in traffic between users and recursives. Recursives cache and aggregate traffic for many users, factors that are commonly assumed to protect end-user privacy above the recursive. We document institutional privacy as a new risk posed by DNS data collected at authoritative servers, even after caching and aggregation by DNS recursives. We are the first to demonstrate this risk by looking at leaks of e-mail exchanges which show communications patterns, and leaks from accessing sensitive websites, both of which can harm an institution's public image. We define a methodology to identify queries from institutions and identify leaks. We show the current practices of prefix-preserving anonymization of IP addresses and aggregation above the recursive are not sufficient to protect institutional privacy, suggesting the need for novel approaches. We demonstrate this claim by applying our methodology to real-world traffic from DNS servers that use partial prefix-preserving anonymization. Our work prompts additional privacy considerations for institutions that run their own resolvers and authoritative server operators that log and share DNS data.
引用
收藏
页码:69 / 75
页数:7
相关论文
共 50 条
  • [1] Assessing the Privacy Risks of Data Sharing in Genomics
    Heeney, C.
    Hawkins, N.
    de Vries, J.
    Boddington, P.
    Kaye, J.
    [J]. PUBLIC HEALTH GENOMICS, 2011, 14 (01) : 17 - 25
  • [2] Privacy Risks from Genomic Data-Sharing Beacons
    Shringarpure, Suyash S.
    Bustamante, Carlos D.
    [J]. AMERICAN JOURNAL OF HUMAN GENETICS, 2015, 97 (05) : 631 - 646
  • [3] Privacy Risks of Sharing Data from Environmental Health Studies
    Boronow, Katherine E.
    Perovich, Laura J.
    Sweeney, Latanya
    Yoo, Ji Su
    Rudel, Ruthann A.
    Brown, Phil
    Brody, Julia Green
    [J]. ENVIRONMENTAL HEALTH PERSPECTIVES, 2020, 128 (01)
  • [4] A Data Sharing Protocol to Minimize Security and Privacy Risks of Cloud Storage in Big Data Era
    Han, Si
    Han, Ke
    Zhang, Shouyi
    [J]. IEEE ACCESS, 2019, 7 : 60290 - 60298
  • [5] Data sharing threatens privacy
    Declan Butler
    [J]. Nature, 2007, 449 : 644 - 644
  • [6] Sharing data - protecting privacy
    不详
    [J]. R&D MAGAZINE, 2006, 48 (06): : 14 - 14
  • [7] Data sharing threatens privacy
    Butler, Declan
    [J]. NATURE, 2007, 449 (7163) : 644 - 645
  • [8] Genetic Data Sharing and Privacy
    Marco D. Sorani
    John K. Yue
    Sourabh Sharma
    Geoffrey T. Manley
    Adam R. Ferguson
    Shelly R. Cooper
    Kristen Dams-O’Connor
    Wayne A. Gordon
    Hester F. Lingsma
    Andrew I. R. Maas
    David K. Menon
    Diane J. Morabito
    Pratik Mukherjee
    David O. Okonkwo
    Ava M. Puccio
    Alex B. Valadka
    Esther L. Yuh
    [J]. Neuroinformatics, 2015, 13 : 1 - 6
  • [9] Genetic Data Sharing and Privacy
    Sorani, Marco D.
    Yue, John K.
    Sharma, Sourabh
    Manley, Geoffrey T.
    Ferguson, Adam R.
    Cooper, Shelly R.
    Dams-O'Connor, Kristen
    Gordon, Wayne A.
    Lingsma, Hester F.
    Maas, Andrew I. R.
    Menon, David K.
    Morabito, Diane J.
    Mukherjee, Pratik
    Okonkwo, David O.
    Puccio, Ava M.
    Valadka, Alex B.
    Yuh, Esther L.
    [J]. NEUROINFORMATICS, 2015, 13 (01) : 1 - 6
  • [10] Reducing Privacy Risks in the Context of Sharing Photos Online
    Hasan, Rakibul
    [J]. CHI'20: EXTENDED ABSTRACTS OF THE 2020 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, 2020,