首页> 外文会议>IFIP/IEEE Symposium on Integrated Network and Service Management >Privacy-Conscious Threat Intelligence Using DNSBLoom
【24h】

Privacy-Conscious Threat Intelligence Using DNSBLoom

机译:使用DNSBLoom的隐私意识威胁情报

获取原文

摘要

The Domain Name System (DNS) is an essential component of every interaction on the Internet. DNS translates human-readable names into machine readable IP addresses. Conversely, DNS requests provide a wealth of information about what goes on in the network. Malicious activity - such as phishing, malware and botnets - also makes use of the DNS. Thus, monitoring DNS traffic is essential for the security team's toolbox. Yet because DNS is so essential to Internet services, tracking DNS is also highly privacy-invasive, as what domain names a user requests reveals their Internet use. Therefore, in an age of comprehensive privacy legislation, such as Europe's GDPR, simply logging every DNS request is not acceptable.In this paper we present DNSBloom, a system that uses Bloom Filters as a privacy-enhancing technology to store DNS requests. Bloom Filters act as a probabilistic set, where a membership test either returns probable membership (with a small false positive probability), or certain non-membership. Because Bloom Filters do not store original information, and because DNSBloom aggregates queries from multiple users over fixed time periods, the system offers strong privacy guarantees while enabling security professionals to check with a high degree of confidence whether certain DNS queries associated with malicious activity have occurred. We validate DNSBloom through three case studies performed on the production DNS infrastructure of a major global research network, and release a working prototype, that integrates with popular DNS resolvers, in open source.
机译:域名系统(DNS)是Internet上每次交互的重要组成部分。 DNS将人类可读的名称转换为机器可读的IP地址。相反,DNS请求可提供有关网络中发生的事情的大量信息。恶意活动(例如网络钓鱼,恶意软件和僵尸网络)也利用DNS。因此,监视DNS流量对于安全团队的工具箱至关重要。但是,由于DNS对于Internet服务至关重要,因此跟踪DNS也是高度侵犯隐私的,因为用户请求的域名显示了他们对Internet的使用。因此,在诸如欧洲GDPR之类的全面隐私立法时代,仅记录每个DNS请求是不可接受的。在本文中,我们介绍了DNSBloom,该系统使用Bloom Blooms作为隐私增强技术来存储DNS请求。布隆过滤器充当概率集,其中成员资格测试要么返回可能的成员资格(假阳性概率很小),要么返回某些非成员资格。由于Bloom Filters不存储原始信息,并且DNSBloom会在固定时间段内聚合来自多个用户的查询,因此该系统提供了强大的隐私保证,同时使安全专业人员可以高度自信地检查是否发生了与恶意活动相关的某些DNS查询。 。我们通过在一个主要全球研究网络的生产DNS基础结构上进行的三个案例研究来验证DNSBloom,并在开放源代码中发布一个与流行的DNS解析器集成的有效原型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号