DocumentCode :
3511427
Title :
Towards Designing Privacy-Preserving Signature-Based IDS as a Service: A Study and Practice
Author :
Yuxin Meng ; Wenjuan Li ; Lam-for Kwok ; Yang Xiang
Author_Institution :
Dept. of Comput. Sci., City Univ. of Hong Kong, Hong Kong, China
fYear :
2013
fDate :
9-11 Sept. 2013
Firstpage :
181
Lastpage :
188
Abstract :
With the advent of Cloud Computing, IDS as a service (IDSaaS) has been proposed as an alternative to protect a network (e.g., financial organization) from a wide range of network attacks by offloading the expensive operations such as the process of signature matching to the cloud. The IDSaaS can be roughly classified into two types: signature-based detection and anomaly-based detection. During the packet inspection, no party wants to disclose their own data especially sensitive information to others, even to the cloud provider, for privacy concerns. However, current solutions of IDSaaS have not much discussed this issue. In this work, focus on the signature-based IDSaaS, we begin by designing a promising privacy-preserving intrusion detection mechanism, the main feature of which is that the process of signature matching does not reveal any specific content of network packets by means of a fingerprint-based comparison. We further conduct a study to evaluate this mechanism under a cloud scenario and identify several open problems and issues for designing such a privacy-preserving mechanism for IDSaaS in a practical environment.
Keywords :
cloud computing; data privacy; digital signatures; IDS-as-a-Service; IDSaaS; anomaly-based detection; cloud computing; cloud provider; fingerprint-based comparison; packet inspection; privacy concerns; privacy-preserving intrusion detection mechanism; privacy-preserving signature; signature matching process; signature-based detection; Cloud computing; Data privacy; Encryption; Inspection; Intrusion detection; Payloads; Cloud Environment; IDSaaS; Intrusion Detection; Network Security; Privacy Preserving; Signature Matching;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Intelligent Networking and Collaborative Systems (INCoS), 2013 5th International Conference on
Conference_Location :
Xi´an
Type :
conf
DOI :
10.1109/INCoS.2013.35
Filename :
6630405
Link To Document :
بازگشت