Title :
Provenance-aware secure networks
Author :
Zhou, Wenchao ; Cronin, E. ; Loo, Thau
Author_Institution :
Univ. of Pennsylvania, Philadelphia, PA
Abstract :
Network accountability and forensic analysis have become increasingly important, as a means of performing network diagnostics, identifying malicious nodes, enforcing trust management policies, and imposing diverse billing over the Internet. This has led to a series of work to provide better network support for accountability, and efficient mechanisms to trace packets and information flows through the Internet. In this paper, we make the following contributions. First, we show that network accountability and forensic analysis can be posed generally as data provenance computations and queries over distributed streams. In particular, one can utilize declarative networks with appropriate security and provenance extensions to provide a unified declarative framework for specifying, analyzing and auditing networks. Second, we propose a taxonomy of data provenance along multiple axes, and show that they map naturally to different use cases in networks. Third, we suggest techniques to efficiently compute and store network provenance, and provide an initial performance evaluation on the P2 declarative networking system with modifications to support authenticated communication and provenance.
Keywords :
DATALOG; Internet; computer network management; distributed databases; message authentication; query processing; telecommunication security; Internet; P2 declarative networking system; authenticated communication; data provenance computation; distributed data stream query; forensic analysis; malicious node identification; network Datalog language; network accountability; network diagnostics; provenance-aware secure network; trust management policy; Computer networks; Data flow computing; Data security; Database languages; Distributed computing; Forensics; IP networks; Information security; Performance analysis; Taxonomy;
Conference_Titel :
Data Engineering Workshop, 2008. ICDEW 2008. IEEE 24th International Conference on
Conference_Location :
Cancun
Print_ISBN :
978-1-4244-2161-9
Electronic_ISBN :
978-1-4244-2162-6
DOI :
10.1109/ICDEW.2008.4498315