EP3854021A1 - Méthode de traitement confidentiel de logs d'un système d'information - Google Patents
Méthode de traitement confidentiel de logs d'un système d'informationInfo
- Publication number
- EP3854021A1 EP3854021A1 EP19790648.0A EP19790648A EP3854021A1 EP 3854021 A1 EP3854021 A1 EP 3854021A1 EP 19790648 A EP19790648 A EP 19790648A EP 3854021 A1 EP3854021 A1 EP 3854021A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- log
- encrypted
- homomorphic
- key
- logs
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000012545 processing Methods 0.000 title claims abstract description 45
- 238000000034 method Methods 0.000 title claims abstract description 29
- 238000004458 analytical method Methods 0.000 claims description 58
- 238000010801 machine learning Methods 0.000 claims description 13
- 230000006870 function Effects 0.000 claims description 11
- 238000001514 detection method Methods 0.000 claims description 9
- 238000013528 artificial neural network Methods 0.000 claims description 5
- 230000003542 behavioural effect Effects 0.000 claims description 4
- 238000013518 transcription Methods 0.000 claims description 4
- 230000035897 transcription Effects 0.000 claims description 4
- 238000013145 classification model Methods 0.000 claims description 3
- 230000000875 corresponding effect Effects 0.000 description 5
- 230000005540 biological transmission Effects 0.000 description 4
- 238000004422 calculation algorithm Methods 0.000 description 4
- 238000004891 communication Methods 0.000 description 4
- 238000010586 diagram Methods 0.000 description 4
- 239000000654 additive Substances 0.000 description 3
- 230000000996 additive effect Effects 0.000 description 3
- 239000003795 chemical substances by application Substances 0.000 description 3
- 230000014509 gene expression Effects 0.000 description 3
- 238000013459 approach Methods 0.000 description 2
- 230000006399 behavior Effects 0.000 description 2
- 238000007635 classification algorithm Methods 0.000 description 2
- 230000002596 correlated effect Effects 0.000 description 2
- 230000000694 effects Effects 0.000 description 2
- 238000005516 engineering process Methods 0.000 description 2
- 238000007477 logistic regression Methods 0.000 description 2
- 238000010606 normalization Methods 0.000 description 2
- 208000018208 Hyperimmunoglobulinemia D with periodic fever Diseases 0.000 description 1
- 206010072219 Mevalonic aciduria Diseases 0.000 description 1
- 230000002159 abnormal effect Effects 0.000 description 1
- 238000013475 authorization Methods 0.000 description 1
- 230000010460 detection of virus Effects 0.000 description 1
- 238000011156 evaluation Methods 0.000 description 1
- 238000011835 investigation Methods 0.000 description 1
- 238000003672 processing method Methods 0.000 description 1
- DTXLBRAVKYTGFE-UHFFFAOYSA-J tetrasodium;2-(1,2-dicarboxylatoethylamino)-3-hydroxybutanedioate Chemical compound [Na+].[Na+].[Na+].[Na+].[O-]C(=O)C(O)C(C([O-])=O)NC(C([O-])=O)CC([O-])=O DTXLBRAVKYTGFE-UHFFFAOYSA-J 0.000 description 1
- 238000012546 transfer Methods 0.000 description 1
- 238000012795 verification Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/008—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols involving homomorphic encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
- H04L9/065—Encryption by serially and continuously modifying data stream elements, e.g. stream cipher systems, RC4, SEAL or A5/3
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3236—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
- H04L9/3242—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving keyed hash functions, e.g. message authentication codes [MACs], CBC-MAC or HMAC
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/46—Secure multiparty computation, e.g. millionaire problem
Definitions
- the present invention relates generally to the field of computer security and more particularly to the management of events and the security of an information system or SIEM (Security Information and Event Management).
- SIEM Security Information and Event Management
- Cybersecurity has become a major issue for owners and users of information systems (IS).
- One of the known approaches for protecting an information system is to collect the events occurring in the various pieces of equipment which constitute it such as routers, servers, firewalls, database, network nodes, etc. Given the frequency, variety and quantity of these events, they cannot generally be treated on the fly. For this reason, events are recorded in system logs, also called logs, for purposes of deferred processing.
- the system logs relating to the various devices are then filtered and then correlated with each other so as to be able to identify the occurrence of anomalies or risk situations and, if necessary, notify the system administrator.
- SIEM Security Information Event Management
- SaaS Software as a Service
- an intrusion detection system can indicate the presence of malware that discloses the identifiers and passwords of users of a certain type of database. The hacker can then use this same malware to recover this confidential data for other databases of the same type.
- SIEM tool can use log information for commercial purposes, for example to identify elements of systems at risk and sell solutions to IT security professionals. He can just as well make a dishonest use of it by informing hackers about potential targets and causing massive attacks on vulnerable components.
- SIEM tools such as IBM TM QRadar TM allow the storage of historical events (ie time-stamped) of an information system on a device external while implementing confidentiality protection measures, such as hash addressing of these events and obfuscation of stored data.
- Other SIEM tools also make it possible to encrypt, by means of a conventional symmetric encryption algorithm such as AES, the data transmitted between their different software components.
- the object of the present invention is therefore to propose a method for processing the logs of an information system which guarantees the confidentiality of the processing as well as the confidentiality of the result of this processing.
- the present invention is defined by a method of processing system logs of an information system comprising a generator of system logs, said system logs being transmitted to a system log analyzer for analysis, the result of the analysis being transmitted to a security operations center to establish a security report or propose a countermeasure to said generator, the system log analyzer and the security operations center being distant from the system log generator, the security operations with a private key (HE.sk) as well as a public key (HE.pk) of a homomorphic cryptosystem, said public key having been previously transmitted to the system log generator and to the system logs, the method according to the invention being particular in that:
- the system log generator generates a symmetric encryption key) and then encrypts this key using the homomorphic encryption public key
- the system log analyzer performs, by means of said encrypted public key, a transcription of the encrypted log to obtain a system log encrypted by the homomorphic encryption public key, then performs a processing of this log in the homomorphic domain to obtain a result analysis in the homomorphic domain (Enc (HE.pk, r)), the analysis result in the homomorphic domain as well as the symmetric key encrypted by the public homomorphic encryption key being transmitted to the security operations center;
- the security operations center decrypts, using the secret key of the homomorphic cryptosystem, the symmetric key encrypted by the homomorphic encryption public key, as well as the analysis result obtained in the homomorphic domain, to obtain respectively the symmetric key and the analysis result in clear, establishes a safety report or proposes a countermeasure from the analysis result in clear, encrypts the safety report or countermeasure using the symmetric key before transmitting the report security or countermeasure thus encrypted to the system log generator;
- the system log generator deciphers, using the symmetric key, the security report or countermeasure thus encrypted, in order to obtain the security report or the countermeasure in clear.
- the information system comprises a generator of system logs (LG), said system logs being transmitted to a system log analyzer (SIEM) for analysis therein, the result of the analysis (r) being intended for the generator of system logs, the system log analyzer being remote from the system log generator, the system log generator having a private key (HE.sk) as well as a public key (HE.pk) from a homomorphic cryptosystem , said public key having been previously transmitted to the system log analyzer, the system log generator generates a symmetric encryption key (K) then encrypts this key using the homomorphic encryption public key (HE.pk) and transmits the public key thus encrypted (Enc (HE.pk, K ⁇ )) t> V system log analyzer;
- LG system log analyzer
- the system log generator encrypts a system log using the symmetric key (K) and thus transmits it encrypted to the system log analyzer;
- the system log analyzer performs, by means of said encrypted public key, a transcription of the encrypted log to obtain a system log encrypted by the homomorphic encryption public key, then performs a processing of this log in the homomorphic domain to obtain a result analysis in the homomorphic domain (Enc (HE.pk, r)), the analysis result in the homomorphic domain being transmitted to the system log generator;
- the system log generator decrypts, using the secret key of the homomorphic cryptosystem, the analysis result obtained in the homomorphic domain, to obtain the analysis result in clear.
- the system log analyzer transcribes the log encrypted by the symmetric key (Enc [HE.pkJog * )) by encrypting it a second time with the public key of homomorphic encryption, then decrypting the log a second time encrypted in the homomorphic domain, by means of the symmetric key encrypted by the public key of homomorphic encryption (Enc (HE.pk, K sym )),
- Symmetric encryption is preferably stream encryption.
- the log processing in the homomorphic domain can be an analysis of events by signatures or a behavioral analysis of at least one element of the information system.
- Log processing in the homomorphic domain can be done by a machine learning method.
- the machine learning method uses a linear classification model or a neural network.
- the system log generator can calculate a fingerprint of the log encrypted by a hash function or a message authentication code, and transmits the fingerprint or MAC code with the log thus encrypted, to the system log analyzer.
- system log generator is part of an operating system intrusion detection system (IDS).
- IDS operating system intrusion detection system
- Fig. 1 schematically represents an infrastructure in which the method for processing system logs according to the present invention can be implemented
- Fig. 2 schematically represents the timing diagram of a method for processing system logs according to a first embodiment of the invention
- Fig. 3 schematically represents the timing diagram of a method for processing system logs according to a second embodiment of the invention.
- an information system comprising a set of devices distributed on one or even several networks connected to the Internet, such as terminals (mobile or not), sensors, gateways, servers, etc.
- the use cases targeted here are not only those of conventional local networks (especially company networks) but also networks of connected objects or loT (Internet of Things), intelligent networks (smart grids), transport systems intelligent or ITS (Intelligent Transportation System), home automation networks, etc.
- the devices in the system can support different types of communication. They can, for example, communicate with each other directly in a peer-to-peer manner or via a local network (device to device communication), they can communicate with a gateway (device to gateway communication), for example to aggregate data in the case of a loT application, and they can finally access via remote Internet servers or even Cloud platforms (device to Cloud communication).
- Some of these devices may be equipped with system log generators.
- intrusion detection devices or IDS Intrusion Detection System
- firewalls, gateways or servers can host such log generators.
- gateways or servers can host such log generators.
- system logs can be stored and analyzed automatically by SIEM tools hosted by servers or Cloud platforms.
- the results of this automatic analysis can be used by security operations centers or SOC (Security Operations Center). These security centers can generate reports, propose or deploy countermeasures to remedy possible failures (deployment of a patch or quarantine, for example)
- Fig. 1 schematically represents a system log management infrastructure on which the method of processing system logs according to the present invention can be implemented.
- This figure shows a plurality of devices 110, such as for example workstations, terminals, sensors, gateways, firewalls, servers forming part of an information system. These devices can be linked together by wired or wireless links within a local network and / or connected to the Internet via a gateway, 120. Some of these devices (shown in gray) can be equipped with log generators. System logs can be transmitted over the Internet to a remote server or to a cloud platform. The components of such a platform are represented in 130 comprising SIEM tools, 131, and / or SOC security centers, 132. A SIEM tool and a security center can be hosted on separate servers or on the same server.
- the log generator is responsible for collecting events affecting the device on which it is hosted and for listing them in a system log.
- the log generator of an intrusion detection system could report events relating to abnormal or suspicious activities on a host machine (HIDS for Host IDS) or a network (NIDS for Network IDS).
- Such a log is in practice in the form of a list of time-stamped events, each event being described by information such as, for example, the type of event, a status of a software or hardware component, a code error.
- the main events are those relating to an authentication or authorization procedure, a connection success or failure, significant network traffic, detection of viruses or critical system errors.
- the log generator can perform a normalization of the system logs before transmitting them. More precisely, the characteristics of the events, for example the timestamp information, the protocol levels, the port numbers, the IP addresses, etc. are filled in different fields of a predetermined format, for example of XML type.
- the system logs are then transmitted on the fly or stored locally to be transmitted on request to the SIEM tool.
- the SIEM tool can include several agents (agent-based SIEM), installed in the log generators, responsible for periodically transmitting the system logs to the analysis module.
- the SIEM tool may not have an agent (SIEM agentless) in which case, it directly receives the system logs from the log generator (s).
- the SIEM tool can take care of the normalization operation if it has not been previously carried out by the log generator.
- the SIEM tool correlates between two or more events from the system log (or from a plurality of system logs received from different log generators).
- the correlation module aims to reconcile events from one source (or from several sources) based on their characteristics, for example their timestamp information, types of events, IP addresses. The events thus reconciled are then supplied to the analysis module of the SIEM tool.
- This analysis can be performed on the basis of a method using predetermined rules (also called signatures) or a behavioral method
- Signature analysis uses a set of rules associated with already known attack scenarios (mainly from feedback). In other words, if the analysis module detects a configuration of events corresponding to such a scenario, it reconciles these events within the same set and associates it with an attack scenario identifier.
- Examples of such rules include the detection of network traffic with a starting or destination address listed as malicious, a number of unsuccessful connection attempts on one or more machines in the system, above a predetermined threshold for a given period of time, the creation of a new user account immediately followed by a connection activity.
- the correlation of events can be carried out on the fly by receiving the events or alternatively by reading the log file.
- the SIEM tool also includes an analysis module for detecting vulnerabilities, identifying risks or incidents, based on the events received and, where appropriate, correlated. It can combine past events with events arriving in real time as well as use information relating to the context in which these events happened.
- the analysis module advantageously uses a machine learning algorithm, typically a classification algorithm, supervised or unsupervised. This classification algorithm can classify combinations of events into the following categories of "normal”, “dangerous” and "unknown”.
- the results of the analysis of the SIEM tool are then provided to the security center, which can propose countermeasures or deploy them automatically.
- the idea underlying the invention is to propose a processing of the log logs after homomorphic transcryption so that the SIEM tool has no possibility of accessing the system logs in the clear.
- a homomorphic encryption makes it possible to carry out operations (in practice arithmetic operations of addition or multiplication) on data without ever revealing them.
- a homomorphic encryption is an encryption (as a general rule asymmetric) Enc pk (of public key pk) verifying the following property:
- the group homomorphism can be a multiplicative homomorphism.
- a homomorphic cipher can be considered as a ring morphism between the clear space (provided with the operations +, x) and the cipher space (provided with the corresponding operations Q, ®).
- Dec ⁇ HE.sk, x instead of Enc pk (a) and Dec sk (x) to designate respectively a homomorphic encryption operation (of a) with the public key HE.pk and homomorphic decryption (of x ) using the private key HE.sk.
- Transciphering is a cryptographic technique making it possible to pass from data encrypted by a first cryptosystem to the same data encrypted by a second cryptosystem, without going through an intermediate step of decryption in the clear space.
- the present secure classification method makes use of a transcryption which makes it possible to pass from a symmetric encryption, advantageously a stream encryption, to a homomorphic encryption.
- a stream encryption is a symmetric encryption in which the message to be encrypted is simply added bit by bit with a stream of key (key stream), generated from a symmetric key.
- Decryption is carried out like encryption, by simple bit-by-bit addition of the encrypted data with the key flow.
- the transcryption operation (3) assumes, however, that decryption in the homomorphic domain, S ⁇ E , is possible, in other words that it can be performed in the homomorphic domain by means of the abovementioned elementary operations q, ®.
- decryption in the homomorphic domain S ⁇ E
- this being carried out by a simple addition with the stream of key, it is understood that this can be carried out in the homomorphic domain by means of the symmetric encrypted key Enc (HE.pk , K sym .
- Fig. 2 schematically represents the timing diagram of a method for processing system logs according to a first embodiment of the invention.
- This processing method can be implemented in a system log management infrastructure as shown in FIG. 1.
- the log generator could be part, for example, of an intrusion detection system, a firewall etc. It is hosted by an element of the information system that should be protected.
- the SIEM log analysis tool and the security operations center are distant from the log generator. They can be located on remote servers or managed as a service by a Cloud platform.
- the security operations center, SOC has generated a secret HE.sk key for homomorphic encryption.
- SOC has an asymmetric homomorphic cryptosystem characterized by the pair of keys (HE.sk, HE.pk).
- the public key HE.pk has been transmitted to the log generator, LG, and to the log analysis tool, SIEM.
- step 210 the log generator, LG, generates a secret key symmetric encryption S.
- This symmetric key can be renewed periodically or after having transmitted a predetermined number of system logs, or even to each new system log.
- the LG generator encrypts the symmetric key using the public key of the homomorphic cryptosystem, and transmits this key, thus encrypted, that is logs.
- the transmission of the encrypted symmetric key Ehe ⁇ HE.rIz, K ⁇ may be prior, concomitant or subsequent to step 220.
- the transmission of the encrypted key will be omitted if it has already been transmitted in a previous step.
- the log analysis tool then transacts in 230 the system log and in 240 performs the processing / analysis of the log on its transcrypted version. More specifically, the SIEM tool first performs homomorphic log encryption already encrypted by the symmetric key, i.e. Enc HE.pk, log * ) then decrypts log * in the homomorphic domain using Enc HE.pk, K sym , ie:
- the processing / analysis of the journal is then carried out in 240 in the homomorphic domain on Enc (HE.pk og) using a machine learning algorithm or ML (Machine Learning) using a classification, for example a linear classification model with binary output (also called logistic regression).
- Enc HE.pk og
- ML Machine Learning
- F classification
- F F in the clear space.
- a presentation of an ML classifier operating within a homomorphic domain can be found in the article by T. Graepel et al. entitled “ML confidential, Machine Learning on encrypted data” published in the work of Kwon T., Lee MK., Kwon D. (eds) Information Security and Cryptology - ICISC 2012. ICISC 2012. Lecture Notes in Computer Science, vol 7839 Springer, Berlin, Heidelberg.
- x (x l , x 2 , ..., x N ) an observation of an event or even a combination of events, where x 1 , ..., x JV are the observed parameters , also called predictor variables. So, for example, these predictor variables could be a number of connection requests, a latency, a number of system errors of a certain type, etc.
- logistic regression generally consists in calculating a SC score function expressed as a linear combination of the N predictive variables x 1 , ..., x JV relative to the observation, that is:
- SC fl jXj + a 2 x 2 + ... + a N x N (5) and classifying this observation according to the comparison of this score function with respect to a threshold value.
- the score function having a linear expression it can be evaluated in the homomorphic domain.
- the comparison can, in some cases, be made in this area.
- the value of the score function is transmitted as a result in the homomorphic domain, the comparison then being carried out by the security operations center, SOC, as we will see below.
- the score function allows you to split the observation space into two zones separated by a hyperplane and to classify an observation in one or the other of these zones. In general, it is possible to divide the observation space into a plurality of zones using a plurality of score functions.
- Enc HE.pk, r
- Enc (HE.pk, r) F HE (Enc (HE.pk, log)) (6)
- step 250 the analysis tool, SIEM, transmits the encrypted result in the homomorphic domain Enc (HE.pk, r), obtained in the previous step, to the security operations center, SOC the symmetric key encrypted by the public key of the homomorphic cryptosystem, ie Ehe ⁇ HE.rIz, K ⁇ , which had been received from the generator of logs, LG. Again, the transmission of this last key can be omitted if it has been previously transmitted to the SOC center with a previous result.
- Enc HE.pk, r
- the SOC center determines in 270 the countermeasure to be applied or establishes a report, denoted C.
- an event could be classified according to the result r, as dangerous, unknown, or harmless and establish a report accordingly.
- it may offer countermeasures, for example quarantine or the deployment of a patch.
- the proposed ratio / countermeasure, C is encrypted in 280 using the symmetric key, this having been previously decrypted using the private key HE.sk:
- the log generator thus obtains the security report / countermeasure in clear.
- the SIEM tool treats system logs confidentially, it does not have access to the content of these logs since it does not have the symmetric key K , nor to the result of the analysis of these logs since it does not have the secret key HE.sk.
- the SOC center also has no access to the content of the newspapers since it only has the result.
- Fig. 3 schematically represents the timing diagram of a method for processing system logs according to a second embodiment of the invention.
- This second embodiment differs from the first in that it does not implement a security operations center.
- the result of the analysis is transmitted directly to the log generator.
- LG has designated the system log generator and SIEM the log analyzer.
- the log analyzer is remote from the information system, that it is hosted by a remote server or that it is provided as a service by a Cloud platform.
- the log generator has generated a secret HE.sk key for homomorphic encryption. In other words, it has a homomorphic cryptosystem (HE.sk, HE.pk). This public key HE.pk has been transmitted (in clear) to the log analyzer, SIEM.
- the log generator In step 310, the log generator generates a secret key of a symmetric encryption method S.
- the symmetric key can be renewed periodically or after having transmitted a predetermined number of system logs.
- it encrypts the symmetric key by means of the public key of the homomorphic cryptosystem, and transmits the key thus encrypted, logs.
- the step of sending this encrypted key at 310 may be earlier, concomitant or later than that of the encrypted log at 320, or even be omitted if the encrypted key has already been sent during a previous log.
- step 330 the log analysis tool performs a transcription of the system log to obtain the encrypted log in the homomorphic domain, Enc (HE.pkJog).
- step 340 the tool performs the processing / analysis of the log on its transcrypted version, Enc (HE.pk og).
- Enc HE.pk og
- This step is identical to step 240, and the same variants envisaged for the first embodiment also find application here.
- the result is obtained in the homomorphic domain, ie Enc (HE.pk, r).
- the log analyzer has access neither to the content of the logs nor to the result of their analysis. If necessary, it can receive and analyze the logs of a plurality of information system log generators.
- MAC message Authentication Code
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Power Engineering (AREA)
- Computer Hardware Design (AREA)
- Debugging And Monitoring (AREA)
- Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Artificial Intelligence (AREA)
- Life Sciences & Earth Sciences (AREA)
- Biomedical Technology (AREA)
- Biophysics (AREA)
- Computational Linguistics (AREA)
- Data Mining & Analysis (AREA)
- Evolutionary Computation (AREA)
- General Health & Medical Sciences (AREA)
- Molecular Biology (AREA)
- General Physics & Mathematics (AREA)
- Mathematical Physics (AREA)
- Software Systems (AREA)
- Health & Medical Sciences (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR1858359A FR3086090B1 (fr) | 2018-09-17 | 2018-09-17 | Methode de traitement confidentiel de logs d'un systeme d'information |
| PCT/FR2019/052152 WO2020058619A1 (fr) | 2018-09-17 | 2019-09-16 | Méthode de traitement confidentiel de logs d'un système d'information |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3854021A1 true EP3854021A1 (fr) | 2021-07-28 |
Family
ID=65494276
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP19790648.0A Pending EP3854021A1 (fr) | 2018-09-17 | 2019-09-16 | Méthode de traitement confidentiel de logs d'un système d'information |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US12160434B2 (fr) |
| EP (1) | EP3854021A1 (fr) |
| FR (1) | FR3086090B1 (fr) |
| WO (1) | WO2020058619A1 (fr) |
Families Citing this family (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113922976A (zh) * | 2020-09-15 | 2022-01-11 | 京东科技控股股份有限公司 | 设备日志传输方法、装置、电子设备及存储介质 |
| CN116348379A (zh) | 2020-09-16 | 2023-06-27 | 德潘徳恩特无人机独立系统有限责任公司 | 用于无人机的后勤站 |
| WO2023121521A1 (fr) * | 2021-12-20 | 2023-06-29 | Telefonaktiebolaget Lm Ericsson (Publ) | Procédés et dispositifs de prise en charge de détection d'anomalie |
| US12362904B2 (en) | 2022-02-18 | 2025-07-15 | Samsung Electronics Co., Ltd. | Homomorphic encryption operation accelerator, and operating method of homomorphic encryption operation accelerator |
| US12035142B2 (en) | 2022-03-21 | 2024-07-09 | Bank Of America Corporation | Systems and methods for dynamic communication channel switching for secure message propagation |
| US12578946B2 (en) | 2022-04-19 | 2026-03-17 | Bank Of America Corporation | System and method for dynamic code patch deployment within a distributed network |
| JP7819648B2 (ja) * | 2023-02-15 | 2026-02-25 | トヨタ自動車株式会社 | 情報処理システムおよび情報処理方法 |
Family Cites Families (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013153628A1 (fr) * | 2012-04-11 | 2013-10-17 | 株式会社日立製作所 | Système de traitement de calcul et procédé d'authentification de résultat de calcul |
| US9306738B2 (en) * | 2012-12-21 | 2016-04-05 | Microsoft Technology Licensing, Llc | Managed secure computations on encrypted data |
| FR3057122B1 (fr) * | 2016-10-03 | 2019-08-16 | Orange | Procede et dispositif de detection d'intrusions sur un reseau utilisant un algorithme de chiffrement homomorphe |
| FR3060165B1 (fr) * | 2016-12-09 | 2019-05-24 | Commissariat A L'energie Atomique Et Aux Energies Alternatives | Methode de classification securisee utilisant une operation de transchiffrement |
| WO2018136801A1 (fr) * | 2017-01-20 | 2018-07-26 | Enveil, Inc. | Opérations sécurisées de bout en bout à l'aide d'une matrice d'interrogation |
| EP3883177B1 (fr) * | 2017-05-30 | 2022-07-27 | BE-Invest International SA | Procédé de protection de données générales pour le partage et la mémorisation multicentriques de données sensibles |
| US10498749B2 (en) * | 2017-09-11 | 2019-12-03 | GM Global Technology Operations LLC | Systems and methods for in-vehicle network intrusion detection |
| US11087223B2 (en) * | 2018-07-11 | 2021-08-10 | International Business Machines Corporation | Learning and inferring insights from encrypted data |
-
2018
- 2018-09-17 FR FR1858359A patent/FR3086090B1/fr active Active
-
2019
- 2019-09-16 EP EP19790648.0A patent/EP3854021A1/fr active Pending
- 2019-09-16 WO PCT/FR2019/052152 patent/WO2020058619A1/fr not_active Ceased
- 2019-09-16 US US17/276,725 patent/US12160434B2/en active Active
Also Published As
| Publication number | Publication date |
|---|---|
| FR3086090A1 (fr) | 2020-03-20 |
| WO2020058619A1 (fr) | 2020-03-26 |
| US20220038478A1 (en) | 2022-02-03 |
| FR3086090B1 (fr) | 2022-01-14 |
| US12160434B2 (en) | 2024-12-03 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3854021A1 (fr) | Méthode de traitement confidentiel de logs d'un système d'information | |
| Anderson et al. | Deciphering malware’s use of TLS (without decryption) | |
| Moura et al. | Security and privacy issues of big data | |
| US20230037520A1 (en) | Blockchain schema for secure data transmission | |
| Velan et al. | A survey of methods for encrypted traffic classification and analysis | |
| EP1543648B1 (fr) | Systeme, procede et progiciel pour garantir des transactions electroniques | |
| EP2023533B1 (fr) | Procédé et installation de classification de trafics dans les réseaux IP | |
| US20030204741A1 (en) | Secure PKI proxy and method for instant messaging clients | |
| EP3520012B1 (fr) | Procédé d 'inspection de trafic chiffré avec des trapdoors fournies. | |
| Gomez et al. | Unsupervised detection and clustering of malicious TLS flows | |
| Yeh et al. | A collaborative DDoS defense platform based on blockchain technology | |
| EP3840324B1 (fr) | Liaison série asynchrone sécurisée | |
| FR3057122B1 (fr) | Procede et dispositif de detection d'intrusions sur un reseau utilisant un algorithme de chiffrement homomorphe | |
| Rasic | Anonymization of event logs for network security monitoring | |
| WO2019197780A1 (fr) | Procédés, dispositifs et programmes d'ordinateur pour le chiffrement et le déchiffrement de données pour la transmission ou le stockage de données | |
| Pătraşcu et al. | Cyber security evaluation of critical infrastructures systems | |
| EP3503500B1 (fr) | Procédé pour créer une signature électronique à distance au moyen du protocole fido | |
| Vecna | Troll Patrol: Detecting Blocked Tor Bridges | |
| EP1510904B1 (fr) | Procédé et système d'évaluation du niveau de sécurité de fonctionnement d'un équipement électronique et d'accès conditionnel à des ressources | |
| Long et al. | Cryptographic strength and machine learning security for low complexity IoT sensors | |
| Lundh et al. | Evaluating Security andData Privacy in SmartHome Devices: A Comparative Experimental Study of European andChinese Products | |
| Clark et al. | SoK: Securing Email--A Stakeholder-Based Analysis (Extended Version) | |
| FR3144730A1 (fr) | Procédé de transmission sécurisée d'un élément secret entre un premier équipement de télécommunication et au moins un deuxième équipement de télécommunication | |
| FR3135336A1 (fr) | Methode d’analyse du risque informatique d’un reseau d’interet lie aux echanges avec au moins un reseau tiers | |
| GADGETS et al. | 10th USENIX Security Symposium WASHINGTON, DC AUGUST 13–17, 2001 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20210317 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20230425 |
|
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: COMMISSARIAT A L'ENERGIE ATOMIQUE ET AUX ENERGIESALTERNATIVES |