Skip to main content
Article
Deriving and Measuring DNS-Based Fingerprints
Journal of Information Security and Applications
  • Dae Wook Kim, Wright State University - Main Campus
  • Junjie Zhang, Wright State University - Main Campus
Document Type
Article
Publication Date
10-1-2017
Disciplines
Abstract

In this paper, we study a new privacy risk, namely DNS-based Fingerprints, introduced by passively collected DNS traffic. We intend to derive behavioral fingerprints from DNS traces, where each behavioral fingerprint targets at uniquely identifying its corresponding user and being immune to the change of time. The derived fingerprints have strong privacy implications such as de-anonymizing the DNS traces and tracking users’ locations across different networks. We have proposed a set of new patterns, which collectively form behavioral fingerprints by characterizing a user's DNS activities through three different perspectives including the domain name, the inter-domain relationship, and domains’ temporal behavior. We have performed extensive evaluation based on a large volume of DNS queries collected from a large campus network across three weeks. The experimental results have demonstrated that the proposed DNS-based fingerprints can accomplish high accuracy on revealing network users’ presence in a new DNS stream based on their fingerprint patterns derived from a historical DNS stream. We also experimentally explored the correlation between users’ general network activities and their DNS-based fingerprints.

DOI
10.1016/j.jisa.2017.07.006
Citation Information
Dae Wook Kim and Junjie Zhang. "Deriving and Measuring DNS-Based Fingerprints" Journal of Information Security and Applications Vol. 36 (2017) p. 32 - 42 ISSN: 22142134
Available at: http://works.bepress.com/junjie_zhang/14/