A Privacy-Preserving Infrastructure to Monitor Encrypted DNS Logs

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

In the realm of cybersecurity, logging system and application activity is a crucial technique to detect and understand cyberattacks by identifying Indicators of Compromise (IoCs). Since these logs can take vast amounts of disk space, it can be tempting to delegate their storage to an external service provider. This requires to encrypt the data, so the service provider does not have access to possibly sensitive information. However, this usually makes it impossible to search for relevant information in the encrypted log. To address this predicament, this paper delves into the realm of modern cryptographic tools to reconcile the dual objectives of protecting log data from prying eyes while enabling controlled processing. We propose a comprehensive framework that contextualizes log data and presents several mechanisms to solve the outsourcing problem, allowing searchable encryption, and we apply our approach to DNS logs. Our contributions include the introduction of two novel schemes, namely symmetric and asymmetric, which facilitate efficient and secure retrieval of intrusion detection-related information from encrypted outsourced storage. Furthermore, we conduct extensive experiments on a test bed to evaluate and compare the effectiveness of the different solutions, providing valuable insights into the practical implementation of our proposed infrastructure for monitoring encrypted logs.

Original languageEnglish
Title of host publicationRisks and Security of Internet and Systems - 18th International Conference, CRiSIS 2023, Revised Selected Papers
EditorsAbderrahim Ait Wakrime, Guillermo Navarro-Arribas, Frédéric Cuppens, Nora Cuppens, Redouane Benaini
PublisherSpringer Science and Business Media Deutschland GmbH
Pages185-199
Number of pages15
ISBN (Print)9783031612305
DOIs
Publication statusPublished - 1 Jan 2024
Event18th International Conference on Risks and Security of Internet and Systems, CRiSIS 2023 - Rabat, Morocco
Duration: 6 Dec 20238 Dec 2023

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume14529 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference18th International Conference on Risks and Security of Internet and Systems, CRiSIS 2023
Country/TerritoryMorocco
CityRabat
Period6/12/238/12/23

Keywords

  • Forensics
  • Indicators of Compromise
  • Searchable Encryption

Fingerprint

Dive into the research topics of 'A Privacy-Preserving Infrastructure to Monitor Encrypted DNS Logs'. Together they form a unique fingerprint.

Cite this