A Compliance-Enhancing Approach to Separated Continuous Auditing of Intelligent Endpoints Security in War Potential Network Based on Location-Sensitive Hashing
摘要
The War Potential Network (WPN) is critical infrastructure determining national security. With the recent trend of increasingly tense international situation, frequent occurrences of cyber-attacks, and the proliferation of new intelligent endpoint devices in WPN, the importance of Continuous Auditing (CA) for intelligent endpoints in WPN has become increasingly significant. Several researches have focused on the accuracy of CA. However, the information in WPN intelligent endpoint devices might have sensitive information. Some laws require computer systems to not disclose data containing national secrets, while certain legal regulations demand the protection of personal privacy. In order to meet compliance requirements, specific technologies have to be implemented in CA, while there are existing research gaps in this field. To fill the gap, this research proposed a compliance-enhancing approach based on Locality-Sensitive Hashing (LSH) and clustering method to enhance compliance in CA. In this approach, auditing nodes gathers encoded data which cannot be read by human, while can be analyzed by algorithms to conduct CA. To quantitatively evaluate this approach, this research also introduced an inference attacking method in WPN scenario as threat model. The research also evaluated the influence of the capability of the auditing object and the correctness of the auditing result, to prove our compliance-enhancing approach can achieve relatively good performance in different evaluation dimensions.