DocumentCode
685976
Title
Conditional disclosure of encrypted whitelists for DDoS attack mitigation
Author
Bianchi, G. ; Rajabi, Hamid ; Caponi, Alberto ; Picierro, Giulio
fYear
2013
fDate
9-13 Dec. 2013
Firstpage
200
Lastpage
206
Abstract
Defensive techniques against Internet-scale attacks can significantly benefit from sharing network security data among different domains. One compelling example, proposed in this paper, is the case of whitelists for DDoS mitigation, where domains broadcast, for each possible DDoS target (!), the set of legitimate customers (client IP addresses) whose traffic should not be blocked while a DDoS attack is in progress. However, such a fine-grained whitelist sharing approach appears hardly appealing (to say the least) to operators; not only the indiscriminate sharing of customers´ addresses raises privacy concerns, but also it discloses, to competitor domains, business critical information on the identity and activity of customers. In a previous work, we proposed a cryptographic approach called “conditional data sharing”, devised to permit disclosure of cross-domain shared fine-grained organized subsets of network monitoring data, only when a threshold number of domains are ready to reveal their data. In this paper, we cast such technique to a realistic scenario of whitelist sharing for DDoS mitigation, and we significantly extend the underlying cryptographic approach so as to support disclosure not only for threshold-based policies, but for more general (monotone) access structures.
Keywords
computer network security; cryptography; DDoS mitigation; Internet-scale attacks; client IP addresses; competitor domains; conditional data sharing; cross-domain shared fine-grained organized subsets; cryptographic approach; defensive techniques; domains broadcast; legitimate customers; network monitoring data; network security data sharing; privacy concerns; threshold-based policies; whitelist sharing; Access control; Computer crime; Conferences; Cryptography; IP networks; Monitoring;
fLanguage
English
Publisher
ieee
Conference_Titel
Globecom Workshops (GC Wkshps), 2013 IEEE
Conference_Location
Atlanta, GA
Type
conf
DOI
10.1109/GLOCOMW.2013.6824986
Filename
6824986
Link To Document