TAILIEUCHUNG - SEPIA: Privacy-Preserving Aggregation of Multi-Domain Network Events and Statistics

Existing Grant Funding: Existing grant funding should be evaluated as an alternative to new funds. Congress could also evaluate including minimum cybersecurity protection standards in grant proposals for grantees dealing with issues such as national security, law enforcement, and critical infrastructures as a condition for receiving government funds. These would include general protection standards such as updating computer patches or running anti-virus software that would not be overly burdensome to grant recipients. Insurance: Congress should study whether the insurance industry can help play a role in increasing the level of cybersecurity of firms that purchase. | SEPIA Privacy-Preserving Aggregation of Multi-Domain Network Events and Statistics Martin Burkhart Mario Strasser Dilip Many Xenofontas Dimitropoulos ETH Zurich Switzerland burkhart strasser dmany fontas @ Abstract Secure multiparty computation MPC allows joint privacy-preserving computations on data of multiple parties. Although MPC has been studied substantially building solutions that are practical in terms of computation and communication cost is still a major challenge. In this paper we investigate the practical usefulness of MPC for multi-domain network security and monitoring. We first optimize MPC comparison operations for processing high volume data in near real-time. We then design privacy-preserving protocols for event correlation and aggregation of network traffic statistics such as addition of volume metrics computation of feature entropy and distinct item count. Optimizing performance of parallel invocations we implement our protocols along with a complete set of basic operations in a library called SEPIA. We evaluate the running time and bandwidth requirements of our protocols in realistic settings on a local cluster as well as on PlanetLab and show that they work in near real-time for up to 140 input providers and 9 computation nodes. Compared to implementations using existing general-purpose MPC frameworks our protocols are significantly faster requiring for example 3 minutes for a task that takes 2 days with general-purpose frameworks. This improvement paves the way for new applications of MPC in the area of networking. Finally we run SEPIA s protocols on real traffic traces of 17 networks and show how they provide new possibilities for distributed troubleshooting and early anomaly detection. 1 Introduction A number of network security and monitoring problems can substantially benefit if a group of involved organizations aggregates private data to jointly perform a computation. For example IDS alert correlation . with DOMINO 49 .

TÀI LIỆU MỚI ĐĂNG
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.