{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,21]],"date-time":"2026-01-21T14:49:59Z","timestamp":1769006999850,"version":"3.49.0"},"reference-count":49,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2021,10,15]],"date-time":"2021-10-15T00:00:00Z","timestamp":1634256000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"MITRE-USM FFRDC","award":["# 11183"],"award-info":[{"award-number":["# 11183"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2021,12,31]]},"abstract":"<jats:p>Network traces are considered a primary source of information to researchers, who use them to investigate research problems such as identifying user behavior, analyzing network hierarchy, maintaining network security, classifying packet flows, and much more. However, most organizations are reluctant to share their data with a third party or the public due to privacy concerns. Therefore, data anonymization prior to sharing becomes a convenient solution to both organizations and researchers. Although several anonymization algorithms are available, few of them allow sufficient privacy (organization need), acceptable data utility (researcher need), and efficient data analysis at the same time. This article introduces a condensation-based differential privacy anonymization approach that achieves an improved tradeoff between privacy and utility compared to existing techniques and produces anonymized network trace data that can be shared publicly without lowering its utility value. Our solution also does not incur extra computation overhead for the data analyzer. A prototype system has been implemented, and experiments have shown that the proposed approach preserves privacy and allows data analysis without revealing the original data even when injection attacks are launched against it. When anonymized datasets are given as input to graph-based intrusion detection techniques, they yield almost identical intrusion detection rates as the original datasets with only a negligible impact.<\/jats:p>","DOI":"10.1145\/3425401","type":"journal-article","created":{"date-parts":[[2021,10,17]],"date-time":"2021-10-17T01:40:14Z","timestamp":1634434814000},"page":"1-23","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":13,"title":["Anonymization of Network Traces Data through Condensation-based Differential Privacy"],"prefix":"10.1145","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4337-1488","authenticated-orcid":false,"given":"Ahmed","family":"Aleroud","sequence":"first","affiliation":[{"name":"Yarmouk University, Jordan, University of Maryland, Baltimore County, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fan","family":"Yang","sequence":"additional","affiliation":[{"name":"University of Maryland, Baltimore County, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sai Chaithanya","family":"Pallaprolu","sequence":"additional","affiliation":[{"name":"University of Maryland, Baltimore County, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiyuan","family":"Chen","sequence":"additional","affiliation":[{"name":"University of Maryland, Baltimore County, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"George","family":"Karabatis","sequence":"additional","affiliation":[{"name":"University of Maryland, Baltimore County, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,10,15]]},"reference":[{"key":"e_1_3_1_2_2","unstructured":"Center for Applied Internet Data Analysis (CAIDA). 2015. Retrieved from https:\/\/www.caida.org\/tools\/taxonomy\/anonymization.xml."},{"key":"e_1_3_1_3_2","doi-asserted-by":"crossref","first-page":"183","DOI":"10.1007\/978-3-540-24741-8_12","article-title":"A condensation approach to privacy preserving data mining","author":"Aggarwal C. C.","year":"2004","unstructured":"C. C. Aggarwal and S. Y. Philip. 2004. A condensation approach to privacy preserving data mining. In Advances in Database Technology-EDBT 2004. Springer, 183\u2013199.","journal-title":"Advances in Database Technology-EDBT 2004"},{"key":"e_1_3_1_4_2","volume-title":"Proceedings of the ACM SIGMOD International Conference on Management of Data","author":"Agrawal R.","year":"2000","unstructured":"R. Agrawal and R. Srikant. 2000. In Proceedings of the ACM SIGMOD International Conference on Management of Data."},{"key":"e_1_3_1_5_2","first-page":"934","volume-title":"Proceedings of the International Symposium on Secure Virtual Infrastructures Cloud and Trusted Computing","author":"Aleroud A.","year":"2016","unstructured":"A. Aleroud, Z. Chen, and G. Karabatis. 2016. Network trace anonymization using a prefix-preserving condensation-based technique (short paper). In Proceedings of the International Symposium on Secure Virtual Infrastructures Cloud and Trusted Computing (OTM\u201916) Springer International Publishing, 934\u2013942."},{"key":"e_1_3_1_6_2","first-page":"207","volume-title":"IEEE Trans. Syst., Man,Cyber.: Syst","volume":"48","author":"Aleroud A. F.","year":"2018","unstructured":"A. F. Aleroud and G. Karabatis. 2018. Queryable semantics to detect cyber-attacks: A flow-based detection approach. IEEE Trans. Syst., Man,Cyber.: Syst. 48, 2 (2018), 207\u2013223."},{"key":"e_1_3_1_7_2","first-page":"43","volume-title":"Communications and Computer Networks","author":"Brekne T.","year":"2005","unstructured":"T. Brekne and A. \u00c5rnes. 2005. Circumventing IP-address' pseudonymization. In Communications and Computer Networks. ACTA Press, 43\u201348."},{"key":"e_1_3_1_8_2","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1007\/11767831_12","volume-title":"Proceedings of the 5th International Conference on Privacy Enhancing Technologies","author":"Brekne T.","year":"2006","unstructured":"T. Brekne, A. Arnes, and A. \u00d8sleb\u00f8. 2006. Anonymization of IP traffic monitoring data: Attacks on two prefix-preserving anonymization schemes and some proposed remedies. In Proceedings of the 5th International Conference on Privacy Enhancing Technologies (PET\u201905). Springer, 179\u2013196."},{"key":"e_1_3_1_9_2","first-page":"179","volume-title":"Proceedings of the International Workshop on Privacy Enhancing Technologies","author":"Brekne T.","year":"2005","unstructured":"T. Brekne, A. \u00c5rnes, and A. \u00d8sleb\u00f8. 2005. Anonymization of ip traffic monitoring data: Attacks on two prefix-preserving anonymization schemes and some proposed remedies. In Proceedings of the International Workshop on Privacy Enhancing Technologies. Springer, 179\u2013196."},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/1672308.1672310"},{"key":"e_1_3_1_11_2","volume-title":"Proceedings of the Network and Distributed System Security Symposium","author":"Coull S. E.","year":"2008","unstructured":"S. E. Coull, C. V. Wright, A. D. Keromytis, F. Monrose, and M. K. Reiter. 2008. Taming the devil: Techniques for evaluating anonymized network data. In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201908)."},{"key":"e_1_3_1_12_2","first-page":"35","volume-title":"Proceedings of the Network and Distributed System Security Symposium","author":"Coull S. E.","year":"2007","unstructured":"S. E. Coull, C. V. Wright, F. Monrose, M. P. Collins, and M. K. Reiter. 2007. Playing devil's advocate: Inferring sensitive information from anonymized network traces. In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201907). 35\u201347."},{"key":"e_1_3_1_13_2","unstructured":"R. Dahlberg and T. Pulls. 2016. Standardized Syslog Processing: Revisiting Secure Reliable Data Transfer and Message Compression. Retrieved from Karlstads universitet website: http:\/\/urn.kb.se\/resolve?urn=urn:nbn:se:kau:diva-45392."},{"key":"e_1_3_1_14_2","first-page":"173","volume-title":"Proceedings of the IEEE International Conference on Intelligence and Security Informatics","author":"Ding T.","year":"2015","unstructured":"T. Ding, A. Aleroud, and G. Karabatis. 2015. Multi-granular aggregation of network flows for security analysis. In Proceedings of the IEEE International Conference on Intelligence and Security Informatics (ISI\u201915). IEEE, 173\u2013175."},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10618-005-0007-5"},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.5555\/1791834.1791836"},{"issue":"2","key":"e_1_3_1_17_2","article-title":"Crypto-PAn: Cryptography-based prefix-preserving anonymization","volume":"46","author":"Fan J.","year":"2004","unstructured":"J. Fan, J. Xu, and M. H. Ammar. 2004. Crypto-PAn: Cryptography-based prefix-preserving anonymization. Comput. Netw. 46, 2 (2004).","journal-title":"Comput. Netw."},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2004.03.033"},{"key":"e_1_3_1_19_2","volume-title":"Algorithms and Tools for Anonymization of the Internet Traffic","author":"Farah T.","year":"2013","unstructured":"T. Farah. 2013. Algorithms and Tools for Anonymization of the Internet Traffic. Ph.D. Dissertation, Simon Fraser University Applied Sciences: School of Engineering Science."},{"key":"e_1_3_1_20_2","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1145\/1519144.1519147","volume-title":"Proceedings of the 2nd European Workshop on System Security","author":"Foukarakis M.","year":"2009","unstructured":"M. Foukarakis, D. Antoniades, and M. Polychronakis. 2009. Deep packet anonymization. In Proceedings of the 2nd European Workshop on System Security. ACM, 16\u201321."},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1515\/piko.2008.0016"},{"key":"e_1_3_1_22_2","volume-title":"Reference Models for Network Trace Anonymization","author":"Gattani S.","year":"2008","unstructured":"S. Gattani. 2008. Reference Models for Network Trace Anonymization. Master's Thesis. Iowa State University."},{"key":"e_1_3_1_23_2","doi-asserted-by":"crossref","unstructured":"S. Ghiasvand and F. M. Ciorba. 2017. Anonymization of system logs for privacy and storage benefits. arXiv preprint arXiv:1706.04337 .","DOI":"10.1007\/978-3-030-03405-4_11"},{"key":"e_1_3_1_24_2","unstructured":"H. Holen. 2020. RIPE (European IP Networks). Retrieved from https:\/\/www.ripe.net\/."},{"key":"e_1_3_1_25_2","unstructured":"E. Kenneally. 2020. Information marketplace for policy and analysis of cyber-risk & trust. Retrieved from https:\/\/www.dhs.gov\/csd-impact."},{"key":"e_1_3_1_26_2","first-page":"1286","volume-title":"Proceedings of the ACM Symposium on Applied Computing. ACM","author":"King J.","year":"2009","unstructured":"J. King, K. Lakkaraju, and A. Slagell. 2009. A taxonomy and adversarial model for attacks against network log anonymization. In Proceedings of the ACM Symposium on Applied Computing. ACM, 1286\u20131293."},{"key":"e_1_3_1_27_2","unstructured":"E. Kohler. 2017. IPSUMDUMP and IPAGGCREATE. Retrieved from http:\/\/www.read.seas.harvard.edu\/\u223ckohler\/ipsumdump."},{"key":"e_1_3_1_28_2","first-page":"2302","volume-title":"Proceedings of the IEEE International Conference on Communications","author":"Koukis D.","year":"2006","unstructured":"D. Koukis, S. Antonatos, D. Antoniades, E. P. Markatos, and P. Trimintzios. 2006. A generic anonymization framework for network traffic. In Proceedings of the IEEE International Conference on Communications (ICC\u201906) IEEE, 2302\u20132309."},{"key":"e_1_3_1_29_2","volume-title":"Anonymization Techniques for URLs and Filenames","author":"Kuenning G.","year":"2003","unstructured":"G. Kuenning and E. L. Miller. 2003. Anonymization Techniques for URLs and Filenames. Technical Report, TR UCSC-CRL-03-05, University of California at Santa Cruz."},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/1217299.1217302"},{"key":"e_1_3_1_31_2","unstructured":"D. Meyer. 2013. University of Oregon route views project. Retrieved from http:\/\/www.routeviews.org\/."},{"key":"e_1_3_1_32_2","unstructured":"G. Minshall. 1997. Tcpdpriv. Retreived from http:\/\/ita.ee.lbl.gov\/html\/contrib\/tcpdpriv.html."},{"key":"e_1_3_1_33_2","first-page":"459","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"Mohammady M.","year":"2018","unstructured":"M. Mohammady, L. Wang, Y. Hong, H. Louafi, M. Pourzandi, and M. Debbabi. 2018. Preserving both privacy and utility in network trace anonymization. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. 459\u2013474."},{"key":"e_1_3_1_34_2","first-page":"459","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"Mohammady M.","year":"2018","unstructured":"M. Mohammady, L. Wang, Y. Hong, H. Louafi, M. Pourzandi, and M. Debbabi. 2018. Preserving both privacy and utility in network trace anonymization. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. ACM, 459\u2013474."},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/1111322.1111330"},{"key":"e_1_3_1_36_2","first-page":"339","volume-title":"Proceedings of the Conference on Applications, Technologies, Architectures, and Protocols for Computer Communications","author":"Pang R.","year":"2003","unstructured":"R. Pang and V. Paxson. 2003. A high-level programming environment for packet trace anonymization and transformation. In Proceedings of the Conference on Applications, Technologies, Architectures, and Protocols for Computer Communications. ACM, 339\u2013351."},{"key":"e_1_3_1_37_2","doi-asserted-by":"crossref","first-page":"S90","DOI":"10.1016\/j.diin.2011.05.011","article-title":"Privacy-preserving network flow recording","volume":"8","author":"Shebaro B.","year":"2011","unstructured":"B. Shebaro and J. R. Crandall. 2011. Privacy-preserving network flow recording. Dig. Investig. 8 (2011), S90\u2013S100.","journal-title":"Dig. Investig."},{"key":"e_1_3_1_38_2","volume-title":"Proceedings of the Workshop on Secure Knowledge Management","author":"Slagell A.","year":"2004","unstructured":"A. Slagell, J. Wang, and W. Yurcik. 2004. Network log anonymization: Application of crypto-PAn to Cisco netflows. In Proceedings of the Workshop on Secure Knowledge Management."},{"key":"e_1_3_1_39_2","first-page":"80","volume-title":"Proceedings of the Workshop of the 1st International Conference on Security and Privacy for Emerging Areas in Communication Networks","author":"Slagell A.","year":"2005","unstructured":"A. Slagell and W. Yurcik. 2005. Sharing computer network logs for security and privacy: A motivation for new methodologies of anonymization. In Proceedings of the Workshop of the 1st International Conference on Security and Privacy for Emerging Areas in Communication Networks. IEEE, 80\u201389."},{"key":"e_1_3_1_40_2","first-page":"3","volume-title":"Proceedings of the 20th Large Installation System Administration Conference","author":"Slagell A. J.","year":"2006","unstructured":"A. J. Slagell, K. Lakkaraju, and K. Luo. 2006. FLAIM: A multi-level anonymization framework for computer and network logs. In Proceedings of the 20th Large Installation System Administration Conference (LISA\u201918). 3\u20138."},{"key":"e_1_3_1_41_2","first-page":"37","volume-title":"Proceedings of the Workshop of the 1st International Conference on Security and Privacy for Emerging Areas in Communication Networks","author":"Slagell A. J.","year":"2005","unstructured":"A. J. Slagell, Y. Li, and K. Luo. 2005. Sharing network logs for computer forensics: A new tool for the anonymization of netflow records. In Proceedings of the Workshop of the 1st International Conference on Security and Privacy for Emerging Areas in Communication Networks. IEEE, 37\u201342."},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04968-2_4"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1142\/S0218488502001648"},{"key":"e_1_3_1_44_2","unstructured":"K. Tan J. Yeo M. E. Locasto and D. Kotz. 2011. Catch Clean and Release: A Survey of Obstacles and Opportunities for Network Trace Sanitization. Dartmouth Scholarship. 3162. Retrieved from https:\/\/digitalcommons.dartmouth.edu\/facoa\/3162."},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.5555\/1077115"},{"key":"e_1_3_1_46_2","author":"Van Dijkhuizen N.","year":"2015","unstructured":"N. Van Dijkhuizen and J. Van Der Ham. 2015. Online event registration with minimal privacy violation. A study into Privacy Enhanced Filtering Techniques. University of Amsterdam. Retrieved from https:\/\/homepages.staff.os3.nl\/\u223cdelaat\/rp\/2014-2015\/p95\/report.pdf.","journal-title":"A study into Privacy Enhanced Filtering Techniques"},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.21"},{"key":"e_1_3_1_48_2","first-page":"280","volume-title":"Proceedings of the 10th IEEE International Conference on Network Protocols","author":"Xu J.","year":"2002","unstructured":"J. Xu, J. Fan, M. H. Ammar, and S. B. Moon. 2002. Prefix-preserving ip address anonymization: Measurement-based security evaluation and a new cryptography-based scheme. In Proceedings of the 10th IEEE International Conference on Network Protocols. IEEE, 280\u2013289."},{"key":"e_1_3_1_49_2","first-page":"280","volume-title":"Proceedings of the 10th IEEE International Conference on Network Protocols","author":"Xu J.","year":"2002","unstructured":"J. Xu, J. Fan, M. H. Ammar, and S. B. Moon. 2002. Prefix-preserving IP address anonymization: Measurement-based security evaluation and a new cryptography-based scheme. In Proceedings of the 10th IEEE International Conference on Network Protocols. IEEE, 280\u2013289."},{"key":"e_1_3_1_50_2","first-page":"157","volume-title":"Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","author":"Yen T.-F.","year":"2009","unstructured":"T.-F. Yen, X. Huang, F. Monrose, and M. K. Reiter. 2009. Browser fingerprinting from coarse traffic summaries: Techniques and implications. In Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer, 157\u2013175."}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3425401","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3425401","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:31:55Z","timestamp":1750195915000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3425401"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,10,15]]},"references-count":49,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2021,12,31]]}},"alternative-id":["10.1145\/3425401"],"URL":"https:\/\/doi.org\/10.1145\/3425401","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,10,15]]},"assertion":[{"value":"2020-04-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-09-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-10-15","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}