4.5 Article

α-MON: Traffic Anonymizer for Passive Monitoring

期刊

出版社

IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
DOI: 10.1109/TNSM.2021.3057927

关键词

Anonymization; passive measurements; traffic monitoring; privacy

资金

  1. Huawei R&D Center (France)
  2. EU Project PIMCity [871370]
  3. SmartData@PoliTO center for Big Data technologies

向作者/读者索取更多资源

Packet measurements are essential for various applications, but they pose a threat to user privacy. Anonymization is an answer to this challenge, but it comes with challenges and drawbacks, such as reduced data value, protocol diversity considerations, and the need for high-speed real-time execution.
Packet measurements at scale are essential for several applications, such as cyber-security, accounting and troubleshooting. They, however, threaten users' privacy by exposing sensitive information. Anonymization has been the answer to this challenge, i.e., replacing sensitive information with obfuscated copies. Anonymization of packet traces, however, comes with some challenges and drawbacks. First, it reduces the value of data. Second, it requires to consider diverse protocols because information may leak from many non-encrypted fields. Third, it must be performed at high speeds directly at the monitor, to prevent private data from leaking, calling for real-time solutions. We present alpha-MON, a flexible tool for privacy-preserving packet monitoring. It replicates input packet streams to different consumers while anonymizing protocol fields according to flexible policies that cover all protocol layers. Beside classic anonymization mechanisms such as IP address obfuscation, alpha-MON supports z-anonymization, a novel solution to obfuscate rare values that can be uniquely traced back to limited sets of users. Differently from classic anonymization approaches, z-anonymity works on a streaming fashion, with zero delay, operating at high-speed links on a packet-by-packet basis. We quantify the impact of z-anonymity on traffic measurements, finding that it introduces minimal error when it comes to finding heavy-hitter services. We evaluate alpha-MON performance using packet traces collected from an ISP network and show that it achieves a sustainable rate of 40 Gbit/s on a Commercial Off-the Shelf server. alpha-MON is available to the community as an open-source project.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.5
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据