Intrusion detection over encrypted network data

Karaçay, Leyli and Savaş, Erkay and Alptekin, Halit (2020) Intrusion detection over encrypted network data. Computer Journal, 63 (4). pp. 604-619. ISSN 0010-4620 (Print) 1460-2067 (Online)

[thumbnail of bxz111.pdf] PDF
bxz111.pdf
Restricted to Registered users only

Download (692kB) | Request a copy

Abstract

Effective protection against cyber-attacks requires constant monitoring and analysis of system data in an IT infrastructure, such as log files and network packets, which may contain private and sensitive information. Security operation centers (SOC), which are established to detect, analyze and respond to cyber-security incidents, often utilize detection models either for known types of attacks or for anomaly and applies them to the system data for detection. SOC are also motivated to keep their models private to capitalize on the models that are their propriety expertise, and to protect their detection strategies against adversarial machine learning. In this paper, we develop a protocol for privately evaluating detection models on the system data, in which privacy of both the system data and detection models is protected and information leakage is either prevented altogether or quantifiably decreased. Our main approach is to provide an end-to-end encryption for the system data and detection models utilizing lattice-based cryptography that allows homomorphic operations over ciphertext. We employ recent data sets in our experiments which demonstrate that the proposed privacy-preserving intrusion detection system is feasible in terms of execution times and bandwidth requirements and reliable in terms of accuracy.
Item Type: Article
Uncontrolled Keywords: cyber security; intrusion detection systems; lattice-based homomorphic encryption; machine learning; binary decision tree; privacy-preserving data classification
Subjects: Q Science > QA Mathematics > QA075 Electronic computers. Computer science
Divisions: Faculty of Engineering and Natural Sciences > Academic programs > Computer Science & Eng.
Faculty of Engineering and Natural Sciences
Depositing User: Erkay Savaş
Date Deposited: 22 Sep 2020 15:29
Last Modified: 01 Aug 2023 21:32
URI: https://research.sabanciuniv.edu/id/eprint/40595

Actions (login required)

View Item
View Item