原文传递 Supporting Research and Development of Security Technologies through Network and Security Data Collection.
题名: Supporting Research and Development of Security Technologies through Network and Security Data Collection.
作者: Claffy, K.; Fomenkov, M.
关键词: Information exchange, Cybersecurity, Computer networks, Routing protocols, Data analysis, Denial of service attack, Malware, Computer communications, Computer network security, Internet, Digital communications, Cybersecurity, Internet measurements, Data sharing
摘要: Research and development targeted at identifying and mitigating Internet security threats require current network data. To fulfill this need, researchers working for the Center for Applied Internet Data Analysis (CAIDA), a program at the San Diego Supercomputer Center (SDSC) which is based at the University of California, San Diego (UCSD), have been engaged in collecting packet-level data from the UCSD Network Telescope (which monitors a /8 IPv4 darknet), and IPv4 and IPv6 topology data from the Ark infrastructure. We curated and, as necessary, anonymized this data, and shared it with the vetted network and security researchers using the PREDICT/IMPACT portal and legal framework. We have also contributed to community building efforts that were responsive to public and private sector needs in Cybersecurity S and T research. To help further advance cybersecurity research, we provided access to this sensitive data real-time traffic destined for black hole address space using a bring-code-to- data model on CAIDA machines. The major challenges in our approach were: sustainable collection, curation, and storage of large volumes of data, and enabling privacy respecting sharing. To manage privacy risk without sacrificing research utility in our approach to data sharing, we collaborated with the PREDICT/ IMPACT legal team to develop, formalize, test, and use a privacy-sensitive data-sharing framework that integrated proven disclosure control techniques to protect privacy without obliterating all utility in the data, with a policy approach that relies upon standard privacy principles and obligations of researchers and data providers.
报告类型: 科技报告
检索历史
应用推荐