• DocumentCode
    2858744
  • Title

    Privacy-preserving alert correlation: a concept hierarchy based approach

  • Author

    Xu, Dingbang ; Ning, Peng

  • Author_Institution
    Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC
  • fYear
    2005
  • fDate
    5-9 Dec. 2005
  • Lastpage
    546
  • Abstract
    With the increasing security threats from infrastructure attacks such as worms and distributed denial of service attacks, it is clear that the cooperation among different organizations is necessary to defend against these attacks. However, organizations´ privacy concerns for the incident and security alert data require that sensitive data be sanitized before they are shared with other organizations. Such sanitization process usually has negative impacts on intrusion analysis (such as alert correlation). To balance the privacy requirements and the need for intrusion analysis, we propose a privacy-preserving alert correlation approach based on concept hierarchies. Our approach consists of two phases. The first phase is entropy guided alert sanitization, where sensitive alert attributes are generalized to high-level concepts to introduce uncertainty into the dataset with partial semantics. To balance the privacy and the usability of alert data, we propose to guide the alert sanitization process with the entropy or differential entropy of sanitized attributes. The second phase is sanitized alert correlation. We focus on defining similarity functions between sanitized attributes and building attack scenarios from sanitized alerts. Our preliminary experimental results demonstrate the effectiveness of the proposed techniques
  • Keywords
    data privacy; security of data; telecommunication security; computer worm; concept hierarchy based approach; data sanitization process; differential entropy; distributed denial of service attack; entropy guided alert sanitization; infrastructure attack; intrusion analysis; partial semantics; privacy-preserving alert correlation; sanitized alert correlation; security threat; sensitive alert attribute; similarity function; Computer crime; Computer security; Computer worms; Data privacy; Data security; Entropy; Information analysis; Information security; National security; Performance analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 21st Annual
  • Conference_Location
    Tucson, AZ
  • ISSN
    1063-9527
  • Print_ISBN
    0-7695-2461-3
  • Type

    conf

  • DOI
    10.1109/CSAC.2005.45
  • Filename
    1565280