E-DoH: Elegantly Detecting the Depths of Open DoH Service on the Internet

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Dong, Cong, Yang, Jiahai, Li, Yun, Wu, Yue, Chen, Yufan, Li, Chenglong, Jiao, Haoran, Yin, Xia, Liu, Yuling
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866914719632195584
author Dong, Cong
Yang, Jiahai
Li, Yun
Wu, Yue
Chen, Yufan
Li, Chenglong
Jiao, Haoran
Yin, Xia
Liu, Yuling
author_facet Dong, Cong
Yang, Jiahai
Li, Yun
Wu, Yue
Chen, Yufan
Li, Chenglong
Jiao, Haoran
Yin, Xia
Liu, Yuling
contents In recent years, DNS over Encrypted (DoE) methods have been regarded as a novel trend within the realm of the DNS ecosystem. In these DoE methods, DNS over HTTPS (DoH) provides encryption to protect data confidentiality while providing better obfuscation to avoid censorship by multiplexing port 443 with web services. This development introduced certain inconveniences in discovering publicly available DoH services. In this paper, we propose the E-DoH method for elegant and efficient DoH service detection. First, we optimized the probing mechanism to enable a single DoH connection to accomplish multiple tasks including service discovery, correctness validation and dependency construction. Second, we propose an efficient DoH detection tool. This tool can enhance probing efficiency while significantly reduce the required traffic volume. Third, based on the above optimization methods, we conducted an exploration of the IPv4 space and performed an in-depth analysis of DoH based on the collected information. Through experiments, our approach demonstrates a remarkable 80% improvement in time efficiency, and only requires 4%-20% traffic volume to complete the detection task. In wild detection, our approach discovered 46k DoH services, which nearly doubles the number discovered by the state-of-the-art. Based on the collected data, we present several intriguing conclusions about the current DoH service ecosystem.
format Preprint
id arxiv_https___arxiv_org_abs_2403_12363
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle E-DoH: Elegantly Detecting the Depths of Open DoH Service on the Internet
Dong, Cong
Yang, Jiahai
Li, Yun
Wu, Yue
Chen, Yufan
Li, Chenglong
Jiao, Haoran
Yin, Xia
Liu, Yuling
Cryptography and Security
Networking and Internet Architecture
In recent years, DNS over Encrypted (DoE) methods have been regarded as a novel trend within the realm of the DNS ecosystem. In these DoE methods, DNS over HTTPS (DoH) provides encryption to protect data confidentiality while providing better obfuscation to avoid censorship by multiplexing port 443 with web services. This development introduced certain inconveniences in discovering publicly available DoH services. In this paper, we propose the E-DoH method for elegant and efficient DoH service detection. First, we optimized the probing mechanism to enable a single DoH connection to accomplish multiple tasks including service discovery, correctness validation and dependency construction. Second, we propose an efficient DoH detection tool. This tool can enhance probing efficiency while significantly reduce the required traffic volume. Third, based on the above optimization methods, we conducted an exploration of the IPv4 space and performed an in-depth analysis of DoH based on the collected information. Through experiments, our approach demonstrates a remarkable 80% improvement in time efficiency, and only requires 4%-20% traffic volume to complete the detection task. In wild detection, our approach discovered 46k DoH services, which nearly doubles the number discovered by the state-of-the-art. Based on the collected data, we present several intriguing conclusions about the current DoH service ecosystem.
title E-DoH: Elegantly Detecting the Depths of Open DoH Service on the Internet
topic Cryptography and Security
Networking and Internet Architecture
url https://arxiv.org/abs/2403.12363