Ring Signatures for Privacy-Preserving Cybersecurity Event Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional anonymization techniques are not suitable or practical for analyzing customer events logs in cybersecurity due to the risk of violating privacy, as they often discard or render meaningless the vast majority of data, making it difficult for cybersecurity vendors to process and analyze events logs effectively while ensuring privacy protection.

Innovation Solution

The use of ring signatures to represent personal identifiers in customer events logs, allowing for the identification and retention of candidate features that are not attributed to a specific customer, thereby discarding private features and retaining public data suitable for cybersecurity operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If conventional anonymization techniques are used to protect customer privacy in events logs, then privacy protection is improved, but the usability and meaningfulness of the data for cybersecurity analysis deteriorates

Engineering Contradiction:
Improveprivacy violation riskVSAvoiddata meaningfulness
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent segments the data processing into distinct phases: first identifying candidate features that occur in groups of events, then analyzing each candidate feature's attribution to specific customers using ring signatures, and finally separating private features (discarded) from public features (retained). This segmentation allows systematic privacy protection without indiscriminately discarding all potentially sensitive data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Ring signatures serve as an intermediary mechanism between the raw customer identifiers and the analysis process. Instead of directly using customer identifiers or completely anonymizing them, ring signatures provide a mathematical structure that allows verification of customer involvement in events while preserving privacy, enabling the system to determine feature attribution without exposing actual customer identities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If all data in events logs is retained for cybersecurity analysis, then analysis effectiveness is improved, but privacy protection deteriorates

Engineering Contradiction:
Improvecybersecurity analysis effectivenessVSAvoidprivacy exposure risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the parameter of customer identifier representation from actual identifiers to ring signatures. This parameter change allows the data to maintain its analytical value for cybersecurity purposes while transforming the privacy-sensitive information into a form that mathematically guarantees privacy protection, enabling both high productivity and privacy protection simultaneously.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If customer identifiers are completely anonymized to protect privacy, then privacy protection is improved, but the ability to trace and analyze security events deteriorates

Engineering Contradiction:
Improvecustomer identity exposureVSAvoidevent traceability
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

Ring signatures act as an intermediary that preserves traceability without exposing identities. The mathematical structure of ring signatures allows the system to trace which customer (among a group) generated a signature and verify their involvement in security events, while the actual customer identity remains hidden. This enables precise event tracing while protecting customer identity information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12019782B1Privacy protection for customer events logs of cybersecurity events
Publication Date: 2024.06.25 TREND MICRO INC
  • US12019782B1 patent drawing
  • US12019782B1 patent drawing
  • US12019782B1 patent drawing

AI summary

System and methods of analyzing customer events logs for cybersecurity with privacy protection are disclosed. Events logs of cybersecurity events are received from customer computers. Customers in the events logs are represented with ring signatures. Candidate features that occur in a group of events are identified in the events logs. A candidate feature is analyzed, based on corresponding ring signatures, to determine if the candidate feature can be attributed to a customer or a limited number of customers. If so, the candidate feature is considered private and is discarded. Otherwise, the candidate feature is retained as public data suitable for use in cybersecurity operations.