DNS Over HTTPS network traffic

Citation Author(s):
Kamil
Jeřábek
Samuel
Stuchlý
Submitted by:
Kamil Jerabek
Last updated:
Mon, 01/17/2022 - 06:55
DOI:
10.21227/96ea-2055
Data Format:
License:
1238 Views
Categories:
Keywords:
5
1 rating - Please login to submit your rating.

Abstract 

Dataset contains generated traffic from single requests towards DNS and DNS over Encryption servers as well as network traffic generated by browsers towards multiple DNS over HTTPS servers. The dataset contains also logs and csv files with queried domains. The IP addresses of the DoH servers are provided in the readme so that users can easily label the data extracted from pcap files. The dataset may be used for Machine Learning purposes (DNS over HTTPS identification).

Instructions: 

Contains captured traffic with request/response queried by Firefox and minority part by Chrome browser.

Queries are generated by different DoH settings in Firefox for purpose of page load time measurement, together with logs.

Different DoH servers in dataset can be identified by ip adresses:

- pi-dns - 88.198.91.187

- google - 8.8.8.8, 8.8.4.4

- cloudflare - 104.16.249.249, 104.16.248.249

- mozilla-cloudflare - 104.16.249.249, 104.16.248.249

- opendns - 146.112.41.2, 146.112.41.3

- cz-nic - 185.43.135.1

- dnslify - 185.235.81.1

- dnsoverhttps-net - 104.236.178.232

- ffmuc - 195.30.94.28, 5.1.66.255

- blahdns - 159.69.198.101

- dnsforge - 176.9.93.198, 176.9.1.117

- other DoH IPs - 104.22.72.65, 104.22.73.65

The dataset also contains traffic generated by Firefox browser repeated 3 times (the same websites were loaded 3 times the same way) .

 

Comments

1

Submitted by rui deng on Mon, 10/23/2023 - 22:16

Dataset Files

LOGIN TO ACCESS DATASET FILES