Skip to content
Book Open access

Unintended Revelations and Risks: Understanding Cellular DNS Leakage on the Public Internet

Oct 2026 · Proceedings of the 2026 ACM Internet Measurement Conference · pp. 636-652 · 0 citations · 68 references

TL;DR

It is shown that an on-path adversary can redirect service-discovery responses once such queries leave the operator's network, which would otherwise be infeasible without the leak, highlighting the need for stricter DNS isolation in cellular networks.

Abstract

Modern cellular networks rely on DNS-based service discovery to select internal control-plane and data-plane functions. Such queries are intended to remain within operators' private namespaces, yet misconfigurations can leak them to the public Internet. Despite warnings from 3GPP and IETF decades ago, the prevalence and security implications of such leakage remain unexamined. We present the first large-scale measurement of cellular service-discovery DNS leakage. By analyzing two days of B-root traffic for each year from 2021 to 2025 and identifying internal cellular queries via 3GPP naming patterns, we observed 13.46 million leaked queries from 139 countries, covering 135,845 unique FQDNs. Most leakage (93.10%) was sporadic, suggesting operators remediated issues over time, yet a small set showed persistent leakage across all five years. Leakage frequently arose in cross-operator and cross-country scenarios, consistent with roaming behavior. While the increased load on B-root is minimal (0.02% on average), leaked names often encode internal deployment parameters (e.g., base-station identifiers), exposing information that operators do not otherwise publish. Using open-source testbeds, we further show that an on-path adversary can redirect service-discovery responses once such queries leave the operator's network, which would otherwise be infeasible without the leak. Our work highlights the need for stricter DNS isolation in cellular networks.

Read PDF

Similar papers

Book Open access Oct 2026

Exploring The Missing Half: A Dual-Perspective Measurement of Encrypted Recursive-to-Authoritative DNS

RFC 9539 defines a unilateral opportunistic mechanism for deploying encrypted DNS on the recursive-to-authoritative link, yet its real-world deployment and operational behavior remain incompletely characterized. Mapping this ecosystem requires complementary observations of both resolver behavior and authoritative capab...

Yu-Jia Zhu, Lin-Kang Zhang, Bai-Yang Li et al. · 0 citations
Book Open access Oct 2026

Securing the Missing Link: Encrypted Recursive-to-Authoritative DNS in the Wild

DNS resolvers increasingly support various encryption protocols, ensuring their communication with end clients remains confidential. The recursive-to-authoritative link has long been overlooked though, despite multiple reports on traffic analysis and response injection by state censors. The experimental RFC 9539 addres...

Yevheniya Nosyk, Simon Fernandez, Andrzej Duda et al. · 1 citation
#software testing Preprint Sep 2026

5G-Shark: A Network Security Auditor for 5G Subscriber Privacy and Unauthenticated Signalling Resilience

5G-Shark is presented, a security assessment tool and methodology that turns a legitimate mobility procedure against the subscriber, and empirical evidence that in several commercial deployments, temporary identifiers are re-allocated in near-sequential steps that keep successive values linkable, a weakness that enable...

Oscar Lasierra, Gines Garcia-Aviles, A. Skarmeta et al. · 0 citations

Sensitive-Topic Leakage Through LLM Routing Metadata: Measurement and Mitigation

LLM routers pick a cheap or expensive model per request by its content, and many gateways and some cloud platforms can log that choice with content logging off. We measure this privacy channel beyond token counts, accounting for noisy labels and repeated prompts. We run pre-registered studies on 1.7 million real reques...

Teng-Ruei Chen · 0 citations
Preprint Aug 2026

Towards Operator-Empowered Vulnerability Hotfixing for 5G Radio Access Networks

Buckle is presented, a framework that enables an MNO to deploy temporary, local, and reversible hotfixes in its radio access network (RAN) during this exposure window and establishes operator-empowered hotfixing as a practical and portable interim defense and delineate the architectural limits of RAN-only prevention.

Dong Hyeok Kim, Xin Zhe Khooi, Hocheol Nam et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.