Sharing Computer Network Logs for Security and Privacy: A Motivation for New Methodologies of Anonymization
Adam J. Slagell, William Yurcik
Abstract
Logs are one of the most fundamental resources to any security professional. It is widely recognized by the government and industry that it is both beneficial and desirable to share logs for the purpose of security research. However, the sharing is not happening or not to the degree or magnitude that is desired. Organizations are reluctant to share logs because of the risk of exposing sensitive information to potential attackers. We believe this reluctance remains high because current anonymization techniques are weak and one-size-fits-all--or better put, one size tries to fit all. We must develop standards and make anonymization available at varying levels, striking a balance between privacy and utility. Organizations have different needs and trust other organizations to different degrees. They must be able to map multiple anonymization levels with defined risks to the trust levels they share with (would-be) receivers. It is not until there are industry standards for multiple levels of anonymization that we will be able to move forward and achieve the goal of widespread sharing of logs for security researchers.
Create a lesson
Related papers
Inference-Engine Fingerprinting Attacks are Practical: Exploring Model-Driven Environmental Discovery, Exploitation, and Escape
Sarah Radway, Andrew Cheng, Vijay Janapa Reddi et al.
Weather Data Spoofing Attacks on Rain-Adaptive Millimeter-Wave Frequency Selection in V2X Communication Networks
Rasheed Bello, Idreez Yusuf, Justice Adjei Owusu et al.
Empirical Analysis of Randomness Quality in Differential Privacy Mechanisms
Cesare Gerolimetto Fabrello, Valeria Rossi, Alberto Trombetta et al.
Towards TEE-Certified DP: Verifiable Differentially Private Training on Legacy GPUs
Li Ge, Wenjie Qu, Weitao Feng et al.
Fingerprinting Multimodal Large Language Models
Chao Huang, Meng Tong, Kejiang Chen
The More It Says, the More You Pay: A Black-Box Audit of Provider-Side Token Inflation in LLM Services
Leilei Chen, Lan Zhang, Chen Tang et al.