vix.ing · top · new · best · stats · spec

Toward Trusted Sharing of Network Packet Traces Using Anonymization: Single-Field Privacy/Analysis Tradeoffs

2007/10/22 by Yurcik, William, Woolam, Clay, Hellings, Greg +2
#C.2.0 #C.2.3 #C.2.m #Cryptography and Security (cs.CR) #D.3.4 #FOS: Computer and information sciences #K.6.5 #Networking and Internet Architecture (cs.NI)

paper · doi:10.48550/arxiv.0710.3979

Abstract

Network data needs to be shared for distributed security analysis. Anonymization of network data for sharing sets up a fundamental tradeoff between privacy protection versus security analysis capability. This privacy/analysis tradeoff has been acknowledged by many researchers but this is the first paper to provide empirical measurements to characterize the privacy/analysis tradeoff for an enterprise dataset. Specifically we perform anonymization options on single-fields within network packet traces and then make measurements using intrusion detection system alarms as a proxy for security analysis capability. Our results show: (1) two fields have a zero sum tradeoff (more privacy lessens security analysis and vice versa) and (2) eight fields have a more complex tradeoff (that is not zero sum) in which both privacy and analysis can both be simultaneously accomplished.

Related