CAIDA Home
 papers | presentations | animations | visualizations | bibliography  
 www.caida.org > publications : bib : networking : entries : yurcik_trusted_sharing.xml
    visit     contact     search:
CAIDA: Cooperative Association for Internet Data Analysis
Bibliography Details

-----summary of contents-----
William Yurcik, Clay Woolam, Greg Hellings, Latifur Khan, and Bhavani~M. Thuraisingham, "Toward Trusted Sharing of Network Packet Traces Using Anonymization: Single-Field Privacy/Analysis Tradeoffs," CoRR, 2007.
-----end summary of contents-----
Toward Trusted Sharing of Network Packet Traces Using Anonymization: Single-Field Privacy/Analysis Tradeoffs
Authors: William Yurcik
Clay Woolam
Greg Hellings
Latifur Khan
Bhavani M. Thuraisingham
Published: CoRR, 2007
URL: http://arxiv.org/abs/0710.3979
ENTRY DATE: 2008-06-16
ABSTRACT: Network data needs to be shared for distributed security analysis. Anonymization of network data for sharing sets up a fundamental tradeoff between privacy protection versus security analysis capability. This privacy/analysis tradeoff has been acknowledged by many researchers but this is the first paper to provide empirical measurements to characterize the privacy/analysis tradeoff for an enterprise dataset. Specifically we perform anonymization options on single-fields within network packet traces and then make measurements using intrusion detection system alarms as a proxy for security analysis capability. Our results show: (1) two fields have a zero sum tradeoff (more privacy lessens security analysis and vice versa) and (2) eight fields have a more complex tradeoff (that is not zero sum) in which both privacy and analysis can both be simultaneously accomplished.

Cooperative Association for Internet Data Analysis (CAIDA)
  Last Modified: Tues Jul-8-2008 14:34:17 PDT
  Maintained by: Alex Ma
  Page URL: http://www.caida.org/publications/bib/networking/entries/yurcik_trusted_sharing.xml