A Graded Approach to Network Forensics with Privacy Concerns

A Graded Approach to Network Forensics with Privacy Concerns
复制标题

考虑隐私问题的网络取证分级方法

DOI:
--
复制
发表时间:
2019
期刊:
International Conference on Computing, Networking and Communications
影响因子:
--
通讯作者:
R. Dutta
R. Dutta
中科院分区:
--
文献类型:
--
作者:
William Brockelsby;R. Dutta

文献摘要

被引文献

相似文献

在最近或历史流量跟踪中的异常检测是应用网络取证来分析网络中先前的安全事件的典型方法,以及用于检测入侵或其他没有已知签名的安全事件的实时网络监控。然而,即使在安全事件发生后,合法用户的隐私期望仍然是一个主要问题。在本文中,我们描述了我们的研究结果,关于网络管理员的偏好发布数据。然后,我们继续描述一种方法,该方法平衡了为合法用户保留最大隐私的动机和获得有关潜在异常行为的最大可能信息的动机。我们的方法基于一种分级方法,从高度匿名的数据到进一步披露目标流量流。特别是,我们表明,它是可能的,以获得显着的进展,从高度聚集的数据,通常被认为是基本上毫无价值的异常检测的目的。我们展示了在真实的企业网络上执行这些第一步的结果,展示了分级方法在实践中如何发挥作用。
Anomaly detection in recent or historic traffic traces is a typical approach in applying network forensics to analyze previous security incidents in networks, as well as for real-time network monitoring for detecting intrusions or other security incidents without known signatures. However, even in the aftermath of a security incident, privacy expectations of legitimate users remain a primary concern. In this paper, we describe our findings regarding the preference of network administrators for releasing data. We then go on to describe a methodology that balances the motivations of preserving maximum privacy for legitimate users and obtaining maximum possible information regarding potentially anomalous behavior. Our methodology is based on a graded approach to progressing from highly anonymized data to further disclosure for targeted traffic streams. In particular, we show that it is possible to obtain significant progress from highly aggregated data that is typically considered essentially valueless for the purpose of anomaly detection. We present the result of these first steps as executed on a real enterprise network, showing how the graded approach can work in practice.