Privacy Preserving Privacy Preserving Netw ork Flow Netw ork Flow Recording Recording
Bilal Bilal Shebaro Shebaro (Computer Science (Computer Science-
- UNM)
UNM) Jedidiah Jedidiah R. Crandall
- R. Crandall (Computer Science
(Computer Science-
- UNM)
Privacy Preserving Privacy Preserving Netw ork Flow Netw ork Flow - - PowerPoint PPT Presentation
Privacy Preserving Privacy Preserving Netw ork Flow Netw ork Flow Recording Recording Bilal Shebaro Shebaro (Computer Science (Computer Science- - UNM) UNM) Bilal Jedidiah R. Crandall R. Crandall (Computer Science (Computer Science- -
– IBE & P.P. semantics for on-the-fly statistics
NetFlow Records Statistical Reports
} Data recorded for the sake of network
} Platforms supported: Cisco IOS, NXOS such as
} Version 5 and version 9 m ost popular
} rather than looking at every packet to
} Netflow version 5 have same sampling
} Netflow version 9 have different
SCR IP DST IP PROTO DST IP PROTO SCR IP DST IP PROTO SCR PORT DST PORT BYTES
individuals’ private data
– IP address + timestamp = public key – Decryption secret is not stored where encrypted data is stored
– Statistical data – Privacy preserving semantics for DB
reasons
for few weeks
network operations
– Regents – Faculty senates – University council
network problem
– Customer Service Department – Auditing department – Enforcing privacy policy organization
controllers
network users could trust in network controllers
Time stamped
IP, IBE(AES-key), AES(flow record) . . . .
Time Period (TP) 12-hours T i m e s t a m p e d Time Period (TP) 12-hours
Merge some records in to the next TP Apply query on more TPs
array with three 6 GB/ s HD (m otherboard RAID controller + PCI Express limited us to read at 3 Gbps from HD)
(TCP-replay was used for that purpose)
encryption and statistical data importion