FINDING · DETECTION

Using the CBOR-based DNS format (application/dns+cbor) reduces DNS message sizes — CBOR DNS queries are at most 136 bytes versus classic DNS queries at 83 bytes for the 99th percentile — but smaller, more uniform packet sizes inadvertently improve classifier accuracy for DNS frame identification, counteracting obfuscation. Reducing packet size and reducing detectability are conflicting goals in packet-format obfuscation.

From 2026-lenders-secrets-best-notSecrets Best Not Shared: DNS Privacy Enhancements for the Constrained IoT · §2 / §4 / §6 · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
ml-classifiertraffic-shape
defenses
randomization

Extracted by claude-sonnet-4-6 — review before relying.