UCL Discovery
UCL home » Library Services » Electronic resources » UCL Discovery

Enhancing IoT Privacy: Why DNS-over-HTTPS Alone Falls Short?

Pelissier, S; Anselmi, G; Mishra, AK; Mandalari, AM; Cunche, M; (2025) Enhancing IoT Privacy: Why DNS-over-HTTPS Alone Falls Short? In: Proceedings of the IEEE International Conference on Trust Security and Privacy in Computing and Communications Trustcom. (pp. pp. 1353-1360). IEEE Green open access

[thumbnail of TrustCom_2024_Encrypted_DNS_IoT.pdf]
Preview
Text
TrustCom_2024_Encrypted_DNS_IoT.pdf - Accepted Version

Download (482kB) | Preview

Abstract

Recent years have seen widespread adoption of consumer Internet of Things (IoT) devices, offering diverse benefits to end-users, from smart homes to healthcare monitoring, but raising serious privacy concerns. To address this, securing efforts, such as encrypting DNS, have been proposedIn this paper, we study the effectiveness of such measures in the specific context of ensuring IoT privacy. We introduce a device identification attack against DNS-over-HTTPS-enabled IoT devices. We conduct more than 25,000 automated experiments across 6 public DNS resolvers and find that the proposed attack can identify devices via DNS-over-HTTPS (DoH) traffic with a 0.98 balanced accuracy. We point out padding as a mitigation technique that reduces identification by a significant 33%. Additionally, we find that half of the evaluated DNS resolvers do not adhere to the relevant specification, substantially compromising user privacy.

Type: Proceedings paper
Title: Enhancing IoT Privacy: Why DNS-over-HTTPS Alone Falls Short?
Event: 2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)
Location: Sanya, China
Dates: 17th- 21st December 2024
Open access status: An open access version is available from UCL Discovery
DOI: 10.1109/TrustCom63139.2024.00189
Publisher version: https://doi.org/10.1109/trustcom63139.2024.00189
Language: English
Additional information: This version is the author accepted manuscript. For information on re-use, please refer to the publisher's terms and conditions.
Keywords: IoT, Privacy, DNS, DoH, Device Identification
UCL classification: UCL
UCL > Provost and Vice Provost Offices > UCL BEAMS
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Electronic and Electrical Eng
URI: https://discovery.ucl.ac.uk/id/eprint/10209660
Downloads since deposit
30Downloads
Download activity - last month
Download activity - last 12 months
Downloads by country - last 12 months

Archive Staff Only

View Item View Item