Private stream searching is a system of cryptographic methods that provide a search facility while preserving the confidentiality of the search criteria and matching documents. This research analyzes the original documentation detection method of the private search system, defines a new detection method based on an appended hash, and presents an analysis of false positives occurring in both methods. Our method offers a lower false positive rate than prior work, and integrates seamlessly into an implementation of private stream searching.
Our contribution defines a conjunction operator for private stream searching. Private stream searching is a system of cryptographic methods that preserves the confidentiality of the search criteria and the result. The system uses an encrypted filter to conceal the search terms, processes a search without decrypting these terms, and saves the result to an encrypted buffer. Fundamentally, the system provides a private search capability based on a logical disjunction of search terms. Our conjunction operator broadens the search capability, and achieves this without significantly increasing the complexity of the private search system. The conjunction is processed as a bit wise summation of hashed keyword values to reference an encrypted entry in the filter. The method is best suited for a conjunction of fields from a record, does not impute a calculation of bilinear map, as required in prior research, and offers a practical utility that integrates into private stream searching. We demonstrate the practicality by including the conjunction operator into our domain specific language for private packet filtering.
Private Packet Filtering (PPF) is a new capability that preserves the confidentiality of sensitive attack indicators, and retrieves network packets that match those indicators without revealing specific indicators or the matching packets. The capability is achieved through the introduction of a high-level language, a conjunction operator that expands the breadth of the language, a simulation of the document detection and recovery rates of the output buffer, and through a description of applicable system facets. Fundamentally, PPF adapts the private stream search system defined by Ostrovsky and Skeith which uses the (partial) homomorphic property of the Paillier cryptosystem. PPF is intended for use in a collaborative environment involving a cyber defender and a partner: The defender has access to a set of sensitive indicators, and is willing to share some of those indicators with the partner. The partner has access to network data, and is willing to share that data. Neither is willing to provide full access. Using the language, the defender creates an encrypted form of the sensitive indicators, and passes the encrypted indicators to the partner. The partner then uses the encrypted indicators to filter packets, and returns an encrypted packet capture file. The partner does not decrypt the indicators and cannot identify which packets matched. The defender decrypts, reassembles the matching packets, gains situational awareness, and notifies the partner of any packets that matched an attack indicator. In this sense, the defender reveals only the matched indicator and retains control of all other indicators. PPF allows both parties to gain situational awareness of malicious activity, and to retain control without exposing every indicator or all network data. Ostrovsky and Skeith introduced the notion of private stream searching in 2005. Their private search system is clever, uses a list of encrypted ones and zeroes to select matching documents, and an output buffer to accumulate non-matching documents as a summation of plaintext zeroes. This buffer optimizes the communication cost of the search and assures that non-matching documents are not transmitted back to client performing the performing search. Using our PPF language, a cyber defender gains access to the underlying private stream search system without significant knowledge of the system or the complexity of its cryptographic methods. The language thus provides a standard representation of a private query for packet filtering that resolves data organization issues and encourages the development of inter-operable implementations. A high level language for private stream searching has not been previously presented.
We present a method to visualize and authenticate a cryptographically negotiated key for a secure phone call. That is, each caller is presented with a graphical representation of the key and through verbal interaction (i.e., side-channel authentication) they describe what they see. If they agree, the key is authenticated and the secure media session continues. The strength of the approach lies in the vocal recognition of the callers, and their ability to confirm the image displayed by their system. The necessary degree of visual recognition is achieved by using basic shapes, color and count. People, regardless of language or age, can easily identifying these images. Our experience shows that they can communicate what they see with little effort and terminate the call when they differ. We believe that this approach reverses the current trend in security to divest users from the underlying cryptographic principles supporting secure systems by abstracting these principles to a comprehensible and visual form. This paper demonstrates that visualization and the human factor can play a pivotal role in establishing a secure communication channel. This short paper discusses how a key is visualized and provides some initial user feedback. We have named this approach the Short Authentication SymbolS VisuallY (SASSY.)
We propose a Progressive Email Classifier (PEC) for high-speed classification of message patterns that are commonly associated with unsolicited bulk email (UNBE). PEC is designed to operate at the network access point, the ingress between the Internet Service Provider (ISP) and the enterprise network; so that a surge of UNBE containing fresh patterns can be detected before they spread into the enterprise network. A real-time scoreboard keeps track of detected feature instances (FI) based on a scoring and aging engine, until they are considered either from valid or UNBE sources. A FI of a valid email is discarded, but an anomalous one is passed to a blacklist to control (e.g., block or defer) subsequent emails containing the FI. The anomaly detector of PEC can be used at different protocol layers. To gain some insights on the performance of PEC, we implemented PEC and integrated it with the sendmail daemon to detect anomalous URL links from email streams. Arbitrarily chosen on-line texts and URL links extracted from a corpus of spamming-phishing emails were used to compose testing emails. Experimental results on a Xeon based server show that PEC can handle 1.2M score/age updates, parse 0.9M URL links (of average size 30 bytes) for hashing and matching, and parsing of 25,000 email bodies of average size 1.5kB per second. The lossy detection system can be easily scaled by progressive selection of detection features and detection thresholds. It can be used alone or as an early screening tool for an existing infrastructure to defeat major UNBE flooding.
This document describes a keyed-MD5 transform to be used in conjunction with the IP Authentication Header [RFC-1826]. The particular transform is based on [HMAC-MD5]. An option is also specified to guard against replay attacks.
: The Micronyx Incorporated TRISPAN has been evaluated by the National Computer Security Center (NCSC). The security features of the TRISPAN were examined against the requirements specified by the Computer Security Subsystem Interpretation of the Department of Defense Trusted Computer System Evaluation Criteria (CSSI) data 16 September 1988. The NCSC evaluation team has determined that the TRISPAN has some 1&A/D2 class features, however, all requirements of a given class must be met for a subsystem to receive that rating. It has been determined that the highest class at which the TRISPAN satisfies all the specified requirements of the CSSI is class 1&A/D., DAC/D, and Audit/D. This report documents the findings of the evaluation.
: The Data Protection System-800/12 (DPS-800/12) is a dial-up security device that provides identification and authentication for a host system. The DPS-800/12 consists of a Controller Card, an optional Printer/Log Card, and from one to twelve Port Cards. The Controller Card uses a microprocessor and contains the DPS-800/12 system program. This card controls the Printer/Log Card and the Port Cards. The Printer/Log Card drives the printer in order to print the audit records. Each Port Card controls a communication line between a modem and the respective host. This report documents the findings of the evaluation. Keywords: Computer security; Computer hardware; NCSC; TCSEC; IA Test and evaluation; Identification authentication; DPS-800/12.
Abstract : The Citadel Security product has been evaluated by the National Computer Security Center (NCSC). Citadel is considered to be a sub-system rather than a complete trusted computer system. Therefore, it was evaluated against a relevant subset of the requirements in the Department of Defense Trusted Computer System Evaluation Criteria, dated December 1985. Specifically, the subset for this evaluation included identification & authentication (I&A), discretionary access control, and audit requirements. The NCSC evaluation team has determined that Citadel, when configured as tested, is capable of providing additional protection mechanisms for the IBM/PC/XT and PC/AT. Citadel requires each user to enter a user ID and a valid password in order to gain access to the computer. Citadel maintains discretionary access control by mediating access to files. In addition, Citadel has the capability to audit system activity. Sub-systems are intended to be implemented on automatic data processing (ADP) systems. Specifically, sub-systems are designed to add a level of assurance to an ADP system that has limited or ineffective security mechanisms.
—Packet filtering is a central facet of cyber defense used to detect adversarial activity on a network. Detection stems from defensive efforts to discover new attack indicators, and efforts to share indicators with collaborating partners. There are instances where the sensitive nature of an indicator prohibits outright disclosure. Our private packet filtering language adapts the concept of private stream searching, and defines a new capability to filter packet data without revealing the indicator or result. The syntax of the language, the code to generate a private query, search and result, and the semantic constraints enforced by the language are presented. A cyber defender retains control of sensitive indicators, and coordinates a response action without revealing every indicator to the partner or risk disclosure to the adversary.
Our contribution defines a conjunction operator for private stream searching, integrates this operator into a high level language, and describes the system facets that achieve a realization of private packet filtering. Private stream searching uses an encrypted filter to conceal search terms, processes a search without decrypting the filter, and saves encrypted results to an output buffer. Our conjunction operator is processed as a bitwise summation of hashed keyword values and as a reference into the filter. The operator thus broadens the search capability, and does not increase the complexity of the private search system. When integrated into the language, cyber defenders can filter packets using sensitive attack indicators, and gain situational awareness without revealing those sensitive indicators.
Alan T. Sherman合作论文数Department of Computer Science and Electrical Engineering (CSEE)
University of Maryland, Baltimore County (UMBC)2
Dhananjay S Phatak合作论文数Baltimore County (UMBC);Computer Science and Electrical Engineering Department, University of Maryland1