TitleCyber-security research by ISPs: A NetFlow and DNS Anonymization Policy
Publication TypeConference Paper
Year of Publication2020
AuthorsFejrskov, M., Pedersen, J. M., Vasilomanolakis, E.
Date PublishedJune 2020
ISBN Number978-1-7281-6428-1
Keywordsanonymization, cyber-security, DNS, IPFIX, ISP, NetFlow, policy-based governance, privacy, pubcrawl, security policies

Internet Service Providers (ISPs) have an economic and operational interest in detecting malicious network activity relating to their subscribers. However, it is unclear what kind of traffic data an ISP has available for cyber-security research, and under which legal conditions it can be used. This paper gives an overview of the challenges posed by legislation and of the data sources available to a European ISP. DNS and NetFlow logs are identified as relevant data sources and the state of the art in anonymization and fingerprinting techniques is discussed. Based on legislation, data availability and privacy considerations, a practically applicable anonymization policy is presented.

Citation Keyfejrskov_cyber-security_2020