A Privacy-Preserving Infrastructure to Monitor Encrypted DNS Logs

Entrée en langue anglaise / English entry Catégorie: Conférence avec actes
Auteurs: Adam Oumar Abdel-rahman, Olivier Levillain et Éric Totel
Date: décembre 2023

In the realm of cybersecurity, logging system and application activity is a crucial technique to detect and understand cyberattacks by identifying Indicators of Compromise (IoCs). Since these logs can take vast amounts of disk space, it can be tempting to delegate their storage to an external service provider. This requires to encrypt the data, so the service provider does not have access to possibly sensitive information. However, this usually makes it impossible to search for relevant information in the encrypted log. To address this predicament, this paper delves into the realm of modern cryptographic tools to reconcile the dual objectives of protecting log data from prying eyes while enabling controlled processing. We propose a comprehensive framework that contextualizes log data and presents several mechanisms to solve the outsourcing problem, allowing searchable encryption, and we apply our approach to DNS logs. Our contributions include the introduction of two novel schemes, namely symmetric and asymmetric, which facilitate efficient and secure retrieval of intrusion detection-related information from encrypted outsourced storage. Furthermore, we conduct extensive experiments on a test bed to evaluate and compare the effectiveness of the different solutions, providing valuable insights into the practical implementation of our proposed infrastructure for monitoring encrypted logs.

Publié dans les actes 18th International Conference on Risks and Security of Internet and Systems (LNCS 14529) (pages 185 à 199)

Présenté lors de la conférence CRiSIS à Rabat, Morocco en décembre 2023

BibTeX Document Présentation