Bunker: A Privacy-Oriented Platform for Network Tracing
نویسندگان
چکیده
ISPs are increasingly reluctant to collect and store raw network traces because they can be used to compromise their customers’ privacy. Anonymization techniques mitigate this concern by protecting sensitive information. Trace anonymization can be performed offline (at a later time) or online (at collection time). Offline anonymization suffers from privacy problems because raw traces must be stored on disk – until the traces are deleted, there is the potential for accidental leaks or exposure by subpoenas. Online anonymization drastically reduces privacy risks but complicates software engineering efforts because trace processing and anonymization must be performed at line speed. This paper presents Bunker, a network tracing system that combines the software development benefits of offline anonymization with the privacy benefits of online anonymization. Bunker uses virtualization, encryption, and restricted I/O interfaces to protect the raw network traces and the tracing software, exporting only an anonymized trace. We present the design and implementation of Bunker, evaluate its security properties, and show its ease of use for developing a complex network tracing application.
منابع مشابه
A Survey on Achieving Source Location Privacy and Network Lifetime Maximization in Wireless Sensor Networks
In recent years, Wireless Sensor Network has drawn considerable attention from research community due to wide range of applications used. The most notable challenge which is threatening the WSN is source location privacy. Preserving the source location means hiding the physical location of the source from the adversaries and increasing difficulty for adversaries in tracing the message path back...
متن کاملBuilding future generation service-oriented information broker networks
Future generation networks target collecting intelligence from multiple sources based on end-users' data and their social interaction in order to draw useful conclusions on enabling users to execute their rights to online privacy. These networks form a rising class of service-oriented broker platforms. Designers and providers of such network platforms during the design and development of their ...
متن کاملAutomating Privacy Enforcement in Cloud Platforms
Privacy in cloud computing is a major concern for individuals, governments, service and platform providers. In this context, the compliance with regards to policies and regulations about personal data protection is essential, but hard to achieve, as the implementation of privacy controls is subject to diverse kinds of errors. In this paper we present how the enforcement of privacy policies can ...
متن کاملRequirement-Oriented Privacy Protection Analysis Architecture in Cloud Computing
—As a new software paradigm, cloud computing provides services dynamically according to user requirements. However, it is difficult to control personal privacy information because of the opening, virtualization, multi-tenancy and service outsourcing characters. Therefore, how to protect user privacy information has become a research focus. In this paper, we propose requirement-oriented privacy...
متن کاملTamper Resistant Network Tracing
Raw network traces can be used to compromise the privacy of Internet users. For this reason, many ISPs are reluctant to collect network traces – they often regard possession of such traces as a liability. To mitigate this concern, anonymization techniques have been developed to protect user-identifying information. While most projects anonymize their traces as a post-processing step (i.e., offl...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2009