Over-Threshold Multiparty Private Set Intersection for Collaborative Network Intrusion Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Arpaci, Onur Eren, Boutaba, Raouf, Kerschbaum, Florian
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915553107509248
author Arpaci, Onur Eren
Boutaba, Raouf
Kerschbaum, Florian
author_facet Arpaci, Onur Eren
Boutaba, Raouf
Kerschbaum, Florian
contents An important function of collaborative network intrusion detection is to analyze the network logs of the collaborators for joint IP addresses. However, sharing IP addresses in plain is sensitive and may be even subject to privacy legislation as it is personally identifiable information. In this paper, we present the privacy-preserving collection of IP addresses. We propose a single collector, over-threshold private set intersection protocol. In this protocol $N$ participants identify the IP addresses that appear in at least $t$ participant's sets without revealing any information about other IP addresses. Using a novel hashing scheme, we reduce the computational complexity of the previous state-of-the-art solution from $O(M(N \log{M}/t)^{2t})$ to $O(t^2M\binom{N}{t})$, where $M$ denotes the dataset size. This reduction makes it practically feasible to apply our protocol to real network logs. We test our protocol using joint networks logs of multiple institutions. Additionally, we present two deployment options: a collusion-safe deployment, which provides stronger security guarantees at the cost of increased communication overhead, and a non-interactive deployment, which assumes a non-colluding collector but offers significantly lower communication costs and applicable to many use cases of collaborative network intrusion detection similar to ours.
format Preprint
id arxiv_https___arxiv_org_abs_2510_12045
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Over-Threshold Multiparty Private Set Intersection for Collaborative Network Intrusion Detection
Arpaci, Onur Eren
Boutaba, Raouf
Kerschbaum, Florian
Cryptography and Security
Networking and Internet Architecture
An important function of collaborative network intrusion detection is to analyze the network logs of the collaborators for joint IP addresses. However, sharing IP addresses in plain is sensitive and may be even subject to privacy legislation as it is personally identifiable information. In this paper, we present the privacy-preserving collection of IP addresses. We propose a single collector, over-threshold private set intersection protocol. In this protocol $N$ participants identify the IP addresses that appear in at least $t$ participant's sets without revealing any information about other IP addresses. Using a novel hashing scheme, we reduce the computational complexity of the previous state-of-the-art solution from $O(M(N \log{M}/t)^{2t})$ to $O(t^2M\binom{N}{t})$, where $M$ denotes the dataset size. This reduction makes it practically feasible to apply our protocol to real network logs. We test our protocol using joint networks logs of multiple institutions. Additionally, we present two deployment options: a collusion-safe deployment, which provides stronger security guarantees at the cost of increased communication overhead, and a non-interactive deployment, which assumes a non-colluding collector but offers significantly lower communication costs and applicable to many use cases of collaborative network intrusion detection similar to ours.
title Over-Threshold Multiparty Private Set Intersection for Collaborative Network Intrusion Detection
topic Cryptography and Security
Networking and Internet Architecture
url https://arxiv.org/abs/2510.12045