Privacy Preserving Passive DNS
Pavlos Papadopoulos, Nikolaos Pitropakis, William J. Buchanan, Owen Lo, and Sokratis Katsikas

TL;DR
This paper introduces a privacy-preserving passive DNS system using Hyperledger Fabric blockchain to securely store DNS data, enabling authorized access and analysis while protecting user privacy.
Contribution
It proposes a novel blockchain-based approach for passive DNS data collection that ensures data privacy and integrity, addressing security concerns in DNS infrastructure.
Findings
Successfully implemented a proof-of-concept system
Ensured data privacy against unauthorized access
Provided immutable, auditable DNS data records
Abstract
The Domain Name System (DNS) was created to resolve the IP addresses of the web servers to easily remembered names. When it was initially created, security was not a major concern; nowadays, this lack of inherent security and trust has exposed the global DNS infrastructure to malicious actors. The passive DNS data collection process creates a database containing various DNS data elements, some of which are personal and need to be protected to preserve the privacy of the end users. To this end, we propose the use of distributed ledger technology. We use Hyperledger Fabric to create a permissioned blockchain, which only authorized entities can access. The proposed solution supports queries for storing and retrieving data from the blockchain ledger, allowing the use of the passive DNS database for further analysis, e.g. for the identification of malicious domain names. Additionally, it…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
