{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/45491"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/45491","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Limiting information exposure in multi-domain monitoring systems","abstract":"Security monitoring systems have been recognized as a fundamental component of security management, and they provide the fundamental building blocks of future reactive and autonomic systems that can automatically respond and adapt to changes in their environment. However, operating security monitoring systems in the complex environment of today's organizations is challenging. The complex structure of many organizations, the use of cloud computing, and the complexity of attacks require monitoring systems that can operate across the organization boundaries to integrate many types of information. However, when multiple security domains are involved, privacy and confidentiality problems create challenges in integrating events across systems. Situational awareness can be impacted, and so can be the ability of future systems to adapt to their environment. Our thesis is that the explicit definition of policies enables the design of multi-domain monitoring systems that protect the confidentiality and the integrity of the monitoring data. We focus on the problem of sharing discrete events across organizations for detecting violations of security policies. We identify several scenarios from real-word policies in which such a multi-domain sharing is necessary. We introduce a novel architecture for monitoring multi-domain systems, and we introduce two complementary approaches for reducing the amount of information to share to a value close to the theoretical minimum. Our results show that our approaches have adequate performance in many monitoring scenarios, and significantly reduces the amount of information to share. Finally, as security monitoring is a fundamental service in modern systems, we provide a security analysis of our architecture. We analyze the impact of attacks on the integrity, availability, and confidentiality of the monitoring data. We show that, in many cases, our monitoring system fails gracefully in case of attacks without the causing catastrophic security failures of centralized systems.","abstract_html":"Security monitoring systems have been recognized as a fundamental component of security management, and they provide the fundamental building blocks of future reactive and autonomic systems that can automatically respond and adapt to changes in their environment. However, operating security monitoring systems in the complex environment of today&#x27;s organizations is challenging. The complex structure of many organizations, the use of cloud computing, and the complexity of attacks require monitoring systems that can operate across the organization boundaries to integrate many types of information. However, when multiple security domains are involved, privacy and confidentiality problems create challenges in integrating events across systems. Situational awareness can be impacted, and so can be the ability of future systems to adapt to their environment. Our thesis is that the explicit definition of policies enables the design of multi-domain monitoring systems that protect the confidentiality and the integrity of the monitoring data. We focus on the problem of sharing discrete events across organizations for detecting violations of security policies. We identify several scenarios from real-word policies in which such a multi-domain sharing is necessary. We introduce a novel architecture for monitoring multi-domain systems, and we introduce two complementary approaches for reducing the amount of information to share to a value close to the theoretical minimum. Our results show that our approaches have adequate performance in many monitoring scenarios, and significantly reduces the amount of information to share. Finally, as security monitoring is a fundamental service in modern systems, we provide a security analysis of our architecture. We analyze the impact of attacks on the integrity, availability, and confidentiality of the monitoring data. We show that, in many cases, our monitoring system fails gracefully in case of attacks without the causing catastrophic security failures of centralized systems.","abstract_has_math":false,"creators":["Montanari, Mirko"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Campbell, Roy H.","Gunter, Carl A.","Sanders, William H.","Ou, Xinming"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2013,"date_issued":"2013-08-22T16:42:01Z","date_published":"2013-08-22T16:42:01Z","updated_at":"2026-07-22T22:25:36Z","subjects":["computer security","policy","compliance monitoring","security monitoring","data sharing"],"languages":["en"],"rights":["Copyright 2013 Mirko Montanari"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/45491","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Campbell, Roy H.","Gunter, Carl A.","Sanders, William H.","Ou, Xinming"]},{"key":"dc:creator","label":"Author","values":["Montanari, Mirko"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2013-08-22T16:42:01Z","2013-08"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["computer security","policy","compliance monitoring","security monitoring","data sharing"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2013 Mirko Montanari"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/45491"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Security monitoring systems have been recognized as a fundamental component of security management, and they provide the fundamental building blocks of future reactive and autonomic systems that can automatically respond and adapt to changes in their environment. However, operating security monitoring systems in the complex environment of today's organizations is challenging. The complex structure of many organizations, the use of cloud computing, and the complexity of attacks require monitoring systems that can operate across the organization boundaries to integrate many types of information. However, when multiple security domains are involved, privacy and confidentiality problems create challenges in integrating events across systems. Situational awareness can be impacted, and so can be the ability of future systems to adapt to their environment. Our thesis is that the explicit definition of policies enables the design of multi-domain monitoring systems that protect the confidentiality and the integrity of the monitoring data. We focus on the problem of sharing discrete events across organizations for detecting violations of security policies. We identify several scenarios from real-word policies in which such a multi-domain sharing is necessary. We introduce a novel architecture for monitoring multi-domain systems, and we introduce two complementary approaches for reducing the amount of information to share to a value close to the theoretical minimum. Our results show that our approaches have adequate performance in many monitoring scenarios, and significantly reduces the amount of information to share. Finally, as security monitoring is a fundamental service in modern systems, we provide a security analysis of our architecture. We analyze the impact of attacks on the integrity, availability, and confidentiality of the monitoring data. We show that, in many cases, our monitoring system fails gracefully in case of attacks without the causing catastrophic security failures of centralized systems.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2013-07-08T20:06:25Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 thesis.zip: 16125134 bytes, checksum: 70df8709f0df7159b0eba1abd0bebfd4 (MD5) montanari_mirko.pdf: 1780817 bytes, checksum: b01014ebe5173ade7cec3184dd969ccb (MD5)","Made available in DSpace on 2013-08-22T16:42:01Z (GMT). No. of bitstreams: 3 Mirko_Montanari.pdf: 1780817 bytes, checksum: b01014ebe5173ade7cec3184dd969ccb (MD5) thesis.zip: 16125134 bytes, checksum: 70df8709f0df7159b0eba1abd0bebfd4 (MD5) license.txt: 4065 bytes, checksum: 004833d65956273a40337837fe12fc90 (MD5)"]},{"key":"dc:title","label":"Title","values":["Limiting information exposure in multi-domain monitoring systems"]}]}],"canonical_facts":{"dc:contributor":["Campbell, Roy H.","Gunter, Carl A.","Sanders, William H.","Ou, Xinming"],"dc:creator":["Montanari, Mirko"],"dc:date":["2013-08-22T16:42:01Z","2013-08"],"dc:description":["Security monitoring systems have been recognized as a fundamental component of security management, and they provide the fundamental building blocks of future reactive and autonomic systems that can automatically respond and adapt to changes in their environment. However, operating security monitoring systems in the complex environment of today's organizations is challenging. The complex structure of many organizations, the use of cloud computing, and the complexity of attacks require monitoring systems that can operate across the organization boundaries to integrate many types of information. However, when multiple security domains are involved, privacy and confidentiality problems create challenges in integrating events across systems. Situational awareness can be impacted, and so can be the ability of future systems to adapt to their environment. Our thesis is that the explicit definition of policies enables the design of multi-domain monitoring systems that protect the confidentiality and the integrity of the monitoring data. We focus on the problem of sharing discrete events across organizations for detecting violations of security policies. We identify several scenarios from real-word policies in which such a multi-domain sharing is necessary. We introduce a novel architecture for monitoring multi-domain systems, and we introduce two complementary approaches for reducing the amount of information to share to a value close to the theoretical minimum. Our results show that our approaches have adequate performance in many monitoring scenarios, and significantly reduces the amount of information to share. Finally, as security monitoring is a fundamental service in modern systems, we provide a security analysis of our architecture. We analyze the impact of attacks on the integrity, availability, and confidentiality of the monitoring data. We show that, in many cases, our monitoring system fails gracefully in case of attacks without the causing catastrophic security failures of centralized systems.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2013-07-08T20:06:25Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 thesis.zip: 16125134 bytes, checksum: 70df8709f0df7159b0eba1abd0bebfd4 (MD5) montanari_mirko.pdf: 1780817 bytes, checksum: b01014ebe5173ade7cec3184dd969ccb (MD5)","Made available in DSpace on 2013-08-22T16:42:01Z (GMT). No. of bitstreams: 3 Mirko_Montanari.pdf: 1780817 bytes, checksum: b01014ebe5173ade7cec3184dd969ccb (MD5) thesis.zip: 16125134 bytes, checksum: 70df8709f0df7159b0eba1abd0bebfd4 (MD5) license.txt: 4065 bytes, checksum: 004833d65956273a40337837fe12fc90 (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/45491"],"dc:language":["en"],"dc:rights":["Copyright 2013 Mirko Montanari"],"dc:subject":["computer security","policy","compliance monitoring","security monitoring","data sharing"],"dc:title":["Limiting information exposure in multi-domain monitoring systems"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:36Z"}