Privacy Leakage of DNS over QUIC: Analysis and Countermeasure
Guannan Hu, Kensuke Fukuda · 2024
Original DNS packets are unencrypted, which leads to information leakage while users visit websites. The adversary could monitor the DNS communication and infer the users' Internet preferences, which may contain private content, such as health, finance, and religion. Although several encrypted DNS protocols have been proposed: DNS over HTTPS (DoH), DNS over TLS (DoT), and DNS over QUIC (DoQ), recent research shows that the adversary could still infer the category of web sites even using DoT and DoH. This paper studies the privacy leakage problem of DoQ protocol with two different DNS recursive resolvers (NextDNS and Bind). We show that the classification performance of the websites is high both in NextDNS and Bind resolvers for identifying whether the category of websites is sensitive. More particularly, we indicate that discriminative features are mainly related to the inter-arrival time of packets and packet length. Therefore, we further investigate two countermeasures that could affect the classification results: adding random delay in responses and padding the DNS payload. 1) We find that mean F1 scores decrease as the delays increase. Specifically, it decreases the classification performance by 21% with NextDNS and 19% (0–300 ms) with Bind. Also, 2) DNS padding decreases the classification performance by 10%. We further investigate the combination of the two countermeasures: both adding random (0-60ms and 0-100ms) delays and padding the DNS payload. We confirm that the combined method could greatly reduce the classification performance, on average 25 % in Bind. These results indicate that adding random time and padding can protect users' information from the website fingerprinting attack, though the random delay might affect the user experiences.