ACM Home Page
Please provide us with feedback. Feedback
Large-scale collection and sanitization of network security data: risks and challenges
Full text PdfPdf (154 KB)
Source
New Security Paradigms Workshop archive
Proceedings of the 2006 workshop on New security paradigms table of contents
Germany
SESSION: Data table of contents
Pages: 57 - 64  
Year of Publication: 2006
ISBN:978-1-59593-923-4
Authors
Phillip Porras  SRI International
Vitaly Shmatikov  The University of Texas at Austin
Sponsor
ACSA : Applied Computer Security Associates
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 19,   Downloads (12 Months): 188,   Citation Count: 2
Additional Information:

abstract   references   cited by   collaborative colleagues  

Tools and Actions: Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1278940.1278949
What is a DOI?

ABSTRACT

Over the last several years, there has been an emerging interest in the development of wide-area data collection and analysis centers to help identify, track, and formulate responses to the ever-growing number of coordinated attacks and malware infections that plague computer networks worldwide. As large-scale network threats continue to evolve in sophistication and extend to widely deployed applications, we expect that interest in collaborative security monitoring infrastructures will continue to grow, because such attacks may not be easily diagnosed from a single point in the network. The intent of this position paper is not to argue the necessity of Internet-scale security data sharing infrastructures, as there is ample research [13, 48, 51, 54, 41, 47, 42] and operational examples [43, 17, 32, 53] that already make this case. Instead, we observe that these well-intended activities raise a unique set of risks and challenges.

We outline some of the most salient issues faced by global network security centers, survey proposed defense mechanisms, and pose several research challenges to the computer security community. We hope that this position paper will serve as a stimulus to spur groundbreaking new research in protection and analysis technologies that can facilitate the collaborative sharing of network security data while keeping data contributors safe and secure.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

1
 
2
Back, A., Goldberg, I., and Shostack, A. Freedom Systems 2.1 security issues and analysis. http://www.freehaven.net/anonbib/cache/freedom21-security.pdf, May 2001.
 
3
 
4
 
5
6
 
7
Burnside, M., and Keromytis, A. Low latency anonymity with mix rings. In Proc. 9th International Information Security Conference (ISC) (2006), pp. 32--45.
 
8
9
 
10
Chawla, S., Dwork, C., McSherry, F., Smith, A., and Wee, H. Towards privacy in public databases. In Proc. 2nd Theory of Cryptography Conference (TCC) (2005), pp. 363--385.
 
11
Chung, S., and Mok, A. Allergy attack against automatic signature generation. In Proc. Recent Advances in Intrusion Detection: 9th International Symposium (RAID) (2006), pp. 61--80.
 
12
 
13
 
14
Dingledine, R., Mathewson, N., and Syverson, P. Reputation in P2P anonymity systems. In Proc. Workshop on Economics of Peer-to-Peer Systems (2003).
 
15
16
 
17
DShield. http://www.dshield.org, 2006.
18
 
19
 
20
21
 
22
 
23
24
 
25
Levine, B., Reiter, M., Wang, C., and Wright, M. Timing attacks in low-latency mix systems. In Proc. 8th International Conference on Financial Cryptography (2004), pp. 251--265.
 
26
 
27
Lipmaa, H. Group signature schemes. http://www.cs.ut.ee/~lipmaa/crypto/link/signature/group.php, 2006.
 
28
Locasto, M., Parekh, J., Keromytis, A., and Stolfo, S. Towards collaborative security and P2P intrusion detection. In Proc. IEEE Information Assurance Workshop (2005), pp. 333--339.
29
30
 
31
 
32
myNetWatchman. http://www.mynetwatchman.com, 2006.
33
 
34
Newsome, J., Karp, B., and Song, D. Paragraph: Thwarting signature learning by training maliciously. In Proc. Recent Advances in Intrusion Detection: 9th International Symposium (RAID) (2006), pp. 81--105.
 
35
36
37
 
38
 
39
 
40
Serjantov, A., and Sewell, P. Passive attack analysis for connection-based anonymity systems. In Proc. 8th European Symposium on Research in Computer Security (2003), vol. 2808 of LNCS, pp. 116--131.
 
41
Slagell, A., and Yurcik, W. Sharing computer network logs for security and privacy: a motivation for new methodologies of anonymization. In Proc. SECOVAL: The Workshop on the Value of Security through Collaboration (2005).
 
42
Spitzner, L. Know your enemy: Honeynets. http://project.honeynet.org/papers/honeynet, 2005.
 
43
Symantec. DeepSight threat management system. http://tms.symantec.com, 2006.
 
44
 
45
Tcpdpriv. Program for eliminating confidential information from traces. http://ita.ee.lbl.gov/html/contrib/tcpdpriv.html, 2006.
46
 
47
Valdes, A., Fong, M., and Skinner, K. Data cube indexing of large-scale Infosec repositories. In Proc. Australian Computer Emergency Response Team Conference (2006).
 
48
 
49
 
50
Wang, G. Bibliography on group-oriented signatures. http://www.i2r.a-star.edu.sg/icsd/staff/guilin/bible/group-oriented.htm, 2006.
 
51
52
 
53
Yegneswaran, V., Barford, P., and Plonka, D. On the design and use of Internet sinks for network abuse monitoring. In Proc. Recent Advances in Intrusion Detection: 7th International Symposium (RAID) (2004), pp. 146--165.
54

Collaborative Colleagues:
Phillip Porras: colleagues
Vitaly Shmatikov: colleagues