Proceedings 2019 Network and Distributed System Security Symposium 2019
DOI: 10.14722/ndss.2019.23186
|View full text |Cite
|
Sign up to set email alerts
|

DNS Cache-Based User Tracking

Abstract: We describe a novel user tracking technique that is based on assigning statistically unique DNS records per user. This new tracking technique is unique in being able to distinguish between machines that have identical hardware and software, and track users even if they use "privacy mode" browsing, or use multiple browsers (on the same machine). The technique overcomes issues related to the caching of DNS answers in resolvers, and utilizes per-device caching of DNS answers at the client. We experimentally demon… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
13
0

Year Published

2019
2019
2023
2023

Publication Types

Select...
4
3
2

Relationship

2
7

Authors

Journals

citations
Cited by 25 publications
(13 citation statements)
references
References 9 publications
0
13
0
Order By: Relevance
“…Despite this significant amount of prior work on online advertising, tracking, and ad-blockers, to the best of our knowledge the impact of advertising-related CNAME cloaking on cookie policies has not been previously investigated in detail. c) DNS Security: DNS is an aging protocol, and efforts to improve its security have been slow and marred by deployment mistakes [32], [20], enabling various attacks [28], [27] and misuse by ISPs [44]. New technologies like DNSover-HTTPS [34] have been proposed for remediation, but deployment has only recently begun.…”
Section: Related Workmentioning
confidence: 99%
“…Despite this significant amount of prior work on online advertising, tracking, and ad-blockers, to the best of our knowledge the impact of advertising-related CNAME cloaking on cookie policies has not been previously investigated in detail. c) DNS Security: DNS is an aging protocol, and efforts to improve its security have been slow and marred by deployment mistakes [32], [20], enabling various attacks [28], [27] and misuse by ISPs [44]. New technologies like DNSover-HTTPS [34] have been proposed for remediation, but deployment has only recently begun.…”
Section: Related Workmentioning
confidence: 99%
“…Yet, the results offer tracking results quite similar to HTTP cookie and affected by browser shutdown. Recently, [24] showed how to track users by their DNS cache. This work shows a tracking method that is not affected by the "golden image", browser restarts or privacy modes, however, it does not survive network changes, and its longevity is typically below one day.…”
Section: Related Work Ipv6 Privacymentioning
confidence: 99%
“…Tracking and analyzing behavioural patterns of users through the use of plaintext domains such as DNS and SNI have been explored extensively in previous works [32][33][34]. As DoH and ESNI have been introduced in 2018, little work has been conducted from a security and privacy angle.…”
Section: Related Workmentioning
confidence: 99%