From Fingerprint to Footprint: Characterizing the Dependencies in Encrypted DNS Infrastructures
摘要
Encrypted DNS protocols—DNS-over-TLS (DoT), DNS-over-HTTPS (DoH), and DNS-over-QUIC (DoQ), have been standardized and widely embraced by the industry to enhance the security and privacy of DNS transmissions. As more software and devices support encrypted DNS protocols, adopting encrypted DNS is fast becoming the prevailing trend in domain name resolution. Despite this growing trend, the dependencies within the encrypted DNS infrastructures remain largely unexplored. Key questions arise regarding the server components and third-party DNS providers that encrypted DNS servers rely on during the resolution process. Understanding these dependencies is essential for gaining a comprehensive view of the encrypted DNS ecosystem and revealing potential vulnerabilities or points of centralization that could impact the robustness and reliability of DNS services. This paper analyzes the dependencies from two critical aspects: the server components and the DNS resolution process. To this end, we perform large-scale measurements on encrypted DNS infrastructures and distinguish the role of servers. Based on the classification results, we extract fingerprints to identify the server components and measure the upstream DNS resolver leveraging the resolution footprints. Our findings show that (i) an encrypted DNS resolver can encompass multiple components that cooperate in the resolution process; (ii) despite the dispersed nature of encrypted DNS entrances, 75.24% of all encrypted DNS resolvers rely on the top 10 DNS providers. The concentration of query forwarding towards specific upstream resolvers signifies a growing concern related to dependencies and centralization in encrypted DNS.