View : 416 Download: 0

Look-Aside at Your Own Risk: Privacy Implications of DNSSEC Look-Aside Validation

Title
Look-Aside at Your Own Risk: Privacy Implications of DNSSEC Look-Aside Validation
Authors
Mohaisen, AzizGu, ZhongshuRen, KuiLi, ZhenhuaKamhoua, Charles A.Njilla, Laurent L.Nyang, DaeHun
Ewha Authors
양대헌
SCOPUS Author ID
양대헌scopus
Issue Date
2020
Journal Title
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING
ISSN
1545-5971JCR Link

1941-0018JCR Link
Citation
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING vol. 17, no. 4, pp. 745 - 759
Keywords
ServersPrivacyPublic keySuperluminescent diodesInternetOperating systemsDomain name systemprivacy leakagedefenses
Publisher
IEEE COMPUTER SOC
Indexed
SCIE; SCOPUS WOS
Document Type
Article
Abstract
The Domain Name System Security Extension (DNSSEC) leverages public-key cryptography to provide data integrity, source authentication, and denial of existence for DNS responses. To complement DNSSEC operations, DNSSEC Look-aside Validation (DLV) is designed for alternative off-path validation. Although DNS privacy attracts a lot of attention, the privacy implications of DLV are not fully investigated and understood. In this paper, we take a first in-depth look into DLV, highlighting its lax specifications and privacy implications. By performing extensive experiments over datasets of domain names under comprehensive experimental settings, our findings firmly confirm the privacy leakages caused by DLV. We discover that a large number of domains that should not be sent to DLV servers are being leaked. We explore the root causes, including the lax specifications of DLV. We also propose two approaches to fix the privacy leakages. Our approaches require trivial modifications to the existing DNS standards, and we demonstrate their cost in terms of latency and communication.
DOI
10.1109/TDSC.2018.2816026
Appears in Collections:
인공지능대학 > 사이버보안학과 > Journal papers
Files in This Item:
There are no files associated with this item.
Export
RIS (EndNote)
XLS (Excel)
XML


qrcode

BROWSE