Passer à la navigation principale Passer à la recherche Passer au contenu principal

A Privacy-Preserving Infrastructure to Monitor Encrypted DNS Logs

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

In the realm of cybersecurity, logging system and application activity is a crucial technique to detect and understand cyberattacks by identifying Indicators of Compromise (IoCs). Since these logs can take vast amounts of disk space, it can be tempting to delegate their storage to an external service provider. This requires to encrypt the data, so the service provider does not have access to possibly sensitive information. However, this usually makes it impossible to search for relevant information in the encrypted log. To address this predicament, this paper delves into the realm of modern cryptographic tools to reconcile the dual objectives of protecting log data from prying eyes while enabling controlled processing. We propose a comprehensive framework that contextualizes log data and presents several mechanisms to solve the outsourcing problem, allowing searchable encryption, and we apply our approach to DNS logs. Our contributions include the introduction of two novel schemes, namely symmetric and asymmetric, which facilitate efficient and secure retrieval of intrusion detection-related information from encrypted outsourced storage. Furthermore, we conduct extensive experiments on a test bed to evaluate and compare the effectiveness of the different solutions, providing valuable insights into the practical implementation of our proposed infrastructure for monitoring encrypted logs.

langue originaleAnglais
titreRisks and Security of Internet and Systems - 18th International Conference, CRiSIS 2023, Revised Selected Papers
rédacteurs en chefAbderrahim Ait Wakrime, Guillermo Navarro-Arribas, Frédéric Cuppens, Nora Cuppens, Redouane Benaini
EditeurSpringer Science and Business Media Deutschland GmbH
Pages185-199
Nombre de pages15
ISBN (imprimé)9783031612305
Les DOIs
étatPublié - 1 janv. 2024
Evénement18th International Conference on Risks and Security of Internet and Systems, CRiSIS 2023 - Rabat, Maroc
Durée: 6 déc. 20238 déc. 2023

Série de publications

NomLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume14529 LNCS
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférence18th International Conference on Risks and Security of Internet and Systems, CRiSIS 2023
Pays/TerritoireMaroc
La villeRabat
période6/12/238/12/23

Empreinte digitale

Examiner les sujets de recherche de « A Privacy-Preserving Infrastructure to Monitor Encrypted DNS Logs ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation