Evaluating the Security of a DNS Query Obfuscation Scheme for Private Web Surfing

被引:0
|
作者
Herrmann, Dominik [1 ]
Maass, Max [1 ]
Federrath, Hannes [1 ]
机构
[1] Univ Hamburg, Dept Comp Sci, Hamburg, Germany
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Domain Name System (DNS) does not provide query privacy. Query obfuscation schemes have been proposed to overcome this limitation, but, so far, they have not been evaluated in a realistic setting. In this paper we evaluate the security of a random set range query scheme in a real-world web surfing scenario. We demonstrate that the scheme does not sufficiently obfuscate characteristic query patterns, which can be used by an adversary to determine the visited websites. We also illustrate how to thwart the attack and discuss practical challenges. Our results suggest that previously published evaluations of range queries may give a false sense of the attainable security, because they do not account for any interdependencies between queries.
引用
收藏
页码:205 / 219
页数:15
相关论文
共 50 条
  • [21] Secure quantum private query with real-time security check
    Yang, Yu-Guang
    Sun, Si-Jia
    Tian, Ju
    Xu, Peng
    OPTIK, 2014, 125 (19): : 5538 - 5541
  • [23] EVALUATING THE SURVIVABILITY AND SECURITY OF COMPLEX WEB SYSTEMS
    Ciuchi, Costel
    Bacivarov, Angelica
    Bacivarov, Joan
    Iancu, Laura
    UNIVERSITY POLITEHNICA OF BUCHAREST SCIENTIFIC BULLETIN SERIES C-ELECTRICAL ENGINEERING AND COMPUTER SCIENCE, 2014, 76 (01): : 119 - 132
  • [24] A Database Security Testing Scheme of Web Application
    Yang Haixia
    Nan Zhihong
    ICCSSE 2009: PROCEEDINGS OF 2009 4TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE & EDUCATION, 2009, : 953 - +
  • [25] A Private Statistic Query Scheme for Encrypted Electronic Medical Record System
    Li, Xianxian
    Fu, Xuemei
    Yu, Feng
    Shi, Zhenkui
    Li, Jie
    Yang, Junhao
    PROCEEDINGS OF THE 2021 IEEE 24TH INTERNATIONAL CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK IN DESIGN (CSCWD), 2021, : 1033 - 1039
  • [26] An integrity verification scheme for DNS zone file based on security impact analysis
    Chandramouli, R
    Rose, S
    21st Annual Computer Security Applications Conference, Proceedings, 2005, : 283 - 292
  • [27] Evaluating the adequacy of private security industry regulation in Finland
    Teemu Santonen
    Jyri Paasonen
    Security Journal, 2017, 30 : 585 - 604
  • [28] Web security for access of private information via the Internet
    Anderson, L
    Rauscher, R
    JOURNAL OF THE AMERICAN MEDICAL INFORMATICS ASSOCIATION, 2001, : 853 - 853
  • [29] Evaluating private security sector market perceptions in Finland
    Santonen, Teemu
    Paasonen, Jyri
    SECURITY JOURNAL, 2015, 28 (03) : 230 - 251
  • [30] Evaluating private security sector market perceptions in Finland
    Teemu Santonen
    Jyri Paasonen
    Security Journal, 2015, 28 : 230 - 251