{"title":"Oblivious Intrusion Detection System","authors":"Mahmoud Abdelhafeez, Mostafa M. I. Taha","doi":"10.1109/HOST54066.2022.9840140","DOIUrl":null,"url":null,"abstract":"Intrusion Detection Systems (IDSs) are capable of monitoring network traffic and matching it against rules. Obliv-ious IDSs perform the same tasks of IDSs while using encrypted rules and producing encrypted results without being able to decrypt the rules or the results. Current implementations to this technology suffer from slow searching speeds and/or lack of generality. In this paper we present a generic approach to implement privacy-preserving intrusion detection system based on hybrid binary gates along with an application algorithm for hybrid text matching. Benchmarking showed a wide variety of trade-offs with minimum searching time of 897 msecs for 1-byte encrypted rule through 10- bytes plaintext.","PeriodicalId":222250,"journal":{"name":"2022 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","volume":"19 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-06-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/HOST54066.2022.9840140","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
Intrusion Detection Systems (IDSs) are capable of monitoring network traffic and matching it against rules. Obliv-ious IDSs perform the same tasks of IDSs while using encrypted rules and producing encrypted results without being able to decrypt the rules or the results. Current implementations to this technology suffer from slow searching speeds and/or lack of generality. In this paper we present a generic approach to implement privacy-preserving intrusion detection system based on hybrid binary gates along with an application algorithm for hybrid text matching. Benchmarking showed a wide variety of trade-offs with minimum searching time of 897 msecs for 1-byte encrypted rule through 10- bytes plaintext.