Analyzing Privacy in Enterprise Packet Trace Anonymization

Analyzing Privacy in Enterprise Packet Trace Anonymization
复制标题

分析企业数据包追踪匿名化中的隐私

DOI:
--
复制
发表时间:
2008
期刊:
Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
D. Towsley
D. Towsley
中科院分区:
--
文献类型:
--
作者:
Bruno Ribeiro;Weifeng Chen;G. Miklau;D. Towsley

文献摘要

被引文献

相似文献

通过跟踪收集进行准确的网络测量对于推进网络设计和维护安全可靠的网络至关重要。不幸的是,向分析师发布网络痕迹受到隐私问题的高度限制。已经提出了几个主机匿名方案来解决这个问题。匿名地址之间前缀关系的保存是跟踪实用程序的一个重要方面,但也会导致跟踪匿名化中的许多漏洞。在这项工作中,我们提出了一种有效的针对保留前缀的匿名痕迹的主机指纹攻击。这种攻击是通用的(包括其他人提出的一系列指纹主机去匿名化攻击)和灵活的(它可以适应保留前缀的匿名化的新变体)。也许最重要的是,我们开发了分析工具,允许数据发布者在对攻击者可用的外部信息进行假设的情况下,量化其踪迹的最坏情况漏洞。使用此分析,我们量化了隐私和替代方案的效用之间的权衡,以完全保留前缀的匿名化。
Accurate network measurement through trace collection is critical for advancing network design and for maintaining secure, reliable networks. Unfortunately, the release of network traces to analysts is highly constrained by privacy concerns. Several host anonymization schemes have been proposed to address this issue. Preservation of prefix relationships among anonymized addresses is an important aspect of trace utility, but also causes a number of vulnerabilities in trace anonymization. In this work we present an efficient host fingerprint attack targeting prefix-preserving anonymized traces. The attack is general (encompassing a range of fingerprinting host de-anonymization attacks proposed by others) and flexible (it can be adapted to emerging variants of prefix-preserving anonymization). Perhaps most importantly, we develop analysis tools that allow data publishers to quantify the worst-case vulnerability of their traces given assumptions about the kind of external information that is available to the adversary. Using this analysis we quantify the trade-off between privacy and utility of alternatives to full prefix-preserving anonymization.