Privacy-Preserving Passive DNS

被引:9
|
作者
Papadopoulos, Pavlos [1 ]
Pitropakis, Nikolaos [1 ]
Buchanan, William J. [1 ]
Lo, Owen [1 ]
Katsikas, Sokratis [2 ,3 ]
机构
[1] Edinburgh Napier Univ, Sch Comp, Edinburgh EH10 5DT, Midlothian, Scotland
[2] Norwegian Univ Sci & Technol, Dept Informat Secur & Commun Technol, N-2815 Gjovik, Norway
[3] Open Univ Cyprus, Fac Pure & Appl Sci, CY-2220 Latsia, Cyprus
关键词
passive DNS (Domain Name System); privacy-preserving; distributed ledger; blockchain; hyperledger fabric; private data collection; BLOCKCHAIN; INTERNET; THINGS;
D O I
10.3390/computers9030064
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The Domain Name System (DNS) was created to resolve the IP addresses of web servers to easily remembered names. When it was initially created, security was not a major concern; nowadays, this lack of inherent security and trust has exposed the global DNS infrastructure to malicious actors. The passive DNS data collection process creates a database containing various DNS data elements, some of which are personal and need to be protected to preserve the privacy of the end users. To this end, we propose the use of distributed ledger technology. We use Hyperledger Fabric to create a permissioned blockchain, which only authorized entities can access. The proposed solution supports queries for storing and retrieving data from the blockchain ledger, allowing the use of the passive DNS database for further analysis, e.g., for the identification of malicious domain names. Additionally, it effectively protects the DNS personal data from unauthorized entities, including the administrators that can act as potential malicious insiders, and allows only the data owners to perform queries over these data. We evaluated our proposed solution by creating a proof-of-concept experimental setup that passively collects DNS data from a network and then uses the distributed ledger technology to store the data in an immutable ledger, thus providing a full historical overview of all the records.
引用
收藏
页码:1 / 16
页数:16
相关论文
共 50 条
  • [1] Demo: PDNS: A Fully Privacy-Preserving DNS
    Xiao, Yunming
    Weng, Chenkai
    Yu, Ruijie
    Liu, Peizhi
    Varvello, Matteo
    Kuzmanovic, Aleksandar
    PROCEEDINGS OF THE 2023 ACM SIGCOMM 2023 CONFERENCE, SIGCOMM 2023, 2023, : 1182 - 1184
  • [2] Evaluation of Two Privacy-Preserving Protocols for the DNS
    Castillo-Perez, Sergio
    Garcia-Alfaro, Joaquin
    PROCEEDINGS OF THE 2009 SIXTH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: NEW GENERATIONS, VOLS 1-3, 2009, : 411 - 416
  • [3] A Privacy-Preserving Infrastructure to Monitor Encrypted DNS Logs
    Abdel-Rahman, Adam Oumar
    Levillain, Olivier
    Totel, Eric
    RISKS AND SECURITY OF INTERNET AND SYSTEMS, CRISIS 2023, 2023, 14529 : 185 - 199
  • [4] Lightweight Privacy-Preserving Passive Measurement for Home Networks
    Zhou, Xuzi
    Calvert, Kenneth L.
    2015 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2015, : 1019 - 1024
  • [5] Two-servers PIR based DNS query scheme with privacy-preserving
    Zhao, Fangming
    Hori, Yoshiaki
    Sakurai, Kouichi
    2007 INTERNATIONAL CONFERENCE ON INTELLIGENT PERVASIVE COMPUTING, PROCEEDINGS, 2007, : 299 - 302
  • [6] On Passive Privacy-Preserving Exposure Notification Using Hash Collisions
    Smith, Phillip
    Sarkar, Shamik
    Patwari, Neal
    Kasera, Sneha
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (09): : 16134 - 16147
  • [7] Learning Phase Mask for Privacy-Preserving Passive Depth Estimation
    Tasneem, Zaid
    Milione, Giovanni
    Tsai, Yi-Hsuan
    Yu, Xiang
    Veeraraghavan, Ashok
    Chandraker, Manmohan
    Pittaluga, Francesco
    COMPUTER VISION, ECCV 2022, PT VII, 2022, 13667 : 504 - 521
  • [8] Privacy-preserving boosting
    Sébastien Gambs
    Balázs Kégl
    Esma Aïmeur
    Data Mining and Knowledge Discovery, 2007, 14 : 131 - 170
  • [9] Privacy-preserving boosting
    Gambs, Sebastien
    Kegl, Balazs
    Aimeur, Esma
    DATA MINING AND KNOWLEDGE DISCOVERY, 2007, 14 (01) : 131 - 170
  • [10] Privacy-Preserving Dijkstra
    Ostrovsky, Benjamin
    ADVANCES IN CRYPTOLOGY - CRYPTO 2024, PT IX, 2024, 14928 : 74 - 110