TY - GEN
T1 - Deep packet anonymization
AU - Foukarakis, Michael
AU - Antoniades, Demetres
AU - Polychronakis, Michalis
PY - 2009/3/31
Y1 - 2009/3/31
N2 - Network traces of Internet attacks are among the most valuable resources for network analysts and security researchers. However, organizations and researchers are usually reluctant to share their network data, as network packets may contain private or sensitive information. To alleviate the problem of information leakage, network traces are often anonymized before being shared. Typical anonymization approaches sanitize, or in some cases completely remove, certain packet header fields, higher-level protocol fields, or even payload information that could reveal the source and destination of an attack incident. Although there exists a variety of network trace anonymiza-tion techniques, in this paper we show that in certain cases they are proven inadequate, because attack traces may contain sensitive information not only in the packet headers and the packet payload, which are both exposed "on the wire," but also in the encrypted payload of the self-decrypting shell-code carried in the attack vector of code-injection attacks. To overcome this limitation, we extend an existing network trace anonymization framework to identify and anonymize sensitive information contained in the shellcode of code-injection attack packets. Our approach takes advantage of the certain structure of widely used shellcode decryption schemes to produce fully anonymized attack traces.
AB - Network traces of Internet attacks are among the most valuable resources for network analysts and security researchers. However, organizations and researchers are usually reluctant to share their network data, as network packets may contain private or sensitive information. To alleviate the problem of information leakage, network traces are often anonymized before being shared. Typical anonymization approaches sanitize, or in some cases completely remove, certain packet header fields, higher-level protocol fields, or even payload information that could reveal the source and destination of an attack incident. Although there exists a variety of network trace anonymiza-tion techniques, in this paper we show that in certain cases they are proven inadequate, because attack traces may contain sensitive information not only in the packet headers and the packet payload, which are both exposed "on the wire," but also in the encrypted payload of the self-decrypting shell-code carried in the attack vector of code-injection attacks. To overcome this limitation, we extend an existing network trace anonymization framework to identify and anonymize sensitive information contained in the shellcode of code-injection attack packets. Our approach takes advantage of the certain structure of widely used shellcode decryption schemes to produce fully anonymized attack traces.
UR - https://www.scopus.com/pages/publications/70349116347
U2 - 10.1145/1519144.1519147
DO - 10.1145/1519144.1519147
M3 - Conference contribution
AN - SCOPUS:70349116347
SN - 9781605584720
T3 - Proceedings of the 2nd European Workshop on System Security, EUROSEC'09
SP - 16
EP - 21
BT - Proceedings of the 2nd European Workshop on System Security, EUROSEC'09
PB - Association for Computing Machinery (ACM)
T2 - 2nd European Workshop on System Security, EUROSEC 2009
Y2 - 31 March 2009 through 31 March 2009
ER -