logo

Encrypted DNS still tells an eavesdropper where to look

ID: bd1416a4-9269-5e7c-8a0c-653635c1fd65

STIX ID: report--bd1416a4-9269-5e7c-8a0c-653635c1fd65

Feed Name: Help Net Security

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Mirko Zorz

...
...

This research study demonstrates that plaintext packet headers and monotonic counters leak information that allows an eavesdropper to identify DNS flows for IoT devices even when DNS is encrypted; classifiers achieved roughly 77–86% accuracy across scenarios. The authors propose header elision (peer-based SCHC rules and small CoAP block sizes), sequence-number/address obfuscation, and timing obfuscation to reduce leakage, and they publish their corpus and code for further study.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.