Guided Research Proposal Anonymization of SNMP traces
نویسنده
چکیده
Simple Network Management Protocol (SNMP) is a protocol to access management and control information of network devices. It is a very lightweight protocol capable of easily monitoring thousands of devices simultaneously. Therefore, SNMP is used extensively in enterprise networks and by ISPs, especially for monitoring purposes. It is believed that SNMP is used differently in different environments and various SNMP agents perform differently. People guess where possible problems might be and do optimizations for assumed bottlenecks. However, it is not understood how exactly SNMP performs in practice, what are the various interactions and where exactly the real problems are as there is no data available to the research community from operators of large networks. The operators are concerned about the privacy of their networks’ users and afraid of providing potential attackers with sensitive information about their network allowing for easier break-ins. The proposed project aims at anonymization of SNMP traces so that SNMP traces could be made available. Being able to remove sensitive data out of SNMP traffic traces and anonymize these traces in such a way that privacy or security of the originating network would not be endangered while still leaving enough information in the anonymized traces to be useful for network research, would be of great help. Obtaining these traces would help clarify how exactly SNMP is used, allow to study interaction patterns of different SNMP implementations, compare performance and evaluate different SNMP approaches.
منابع مشابه
Prefix-Preserving IP Address Anonymization: Measurement-Based Security Evaluation and a New Cryptography-Based Scheme
Real-world traffic traces are crucial for Internet research, but only a very small percentage of traces collected are made public. One major reason why traffic trace owners hesitate to make the traces publicly available is the concern that confidential and private information may be inferred from the trace. In this paper we focus on the problem of anonymizing IP addresses in a trace. More speci...
متن کاملSNMP Trace Analysis Definitions
The Network Management Research Group (NMRG) started an activity to collect traces of the Simple Network Management Protocol (SNMP) from operational networks. To analyze these traces, it is necessary to split potentially large traces into more manageable pieces that make it easier to deal with large data sets and simplify the analysis of the data. This document introduces some common definition...
متن کاملSNMP Trace Analysis: Results of Extra Traces
The Simple Network Management Protocol (SMMP) was introduced in the late 1980s. Since then, several evolutionary protocol changes have taken place, resulting in the SNMP version 3 framework (SNMPv3). Extensive use of SNMP has led to significant practical experience by both network operators and researchers. Since recently, researchers are in the possession of real world SNMP traces. This allows...
متن کاملComparison of Traffic Trace Anonymization Tools
Collecting network traffic traces from deployed networks is one of the basic steps in network research. These traces can be used to study real users, traffic engineering, packet classification, web performance, security application or more general network measurement and simulation. However for security and privacy reason monitored traffic traces have to be modified before they are published. T...
متن کاملA Framework for Utility-Driven Network Trace Anonymization
The publication of network traces is critical for network research but their release is highly constrained by privacy and security concerns. The importance of a framework for anonymizing traces to provide different levels of security and utility to promote trace publication has been identified in the literature. However, the current state-of-art anonymization techniques have failed to provide t...
متن کامل