IP Library Granted Patent US 11,483,294
Granted Patent B2
US 11,483,294 · App. 17/083,290 · Granted Oct 25, 2022

Method for anonymizing network data using differential privacy

Inventors: George Karabatis (Ellicott City, MD); Zhiyuan Chen (Ellicott City, MD); Ahmed Aleroud (Irbid, JO); Fan Yang (Catonsville, MD)
Assignee: UNIVERSITY OF MARYLAND, BALTIMORE COUNTY
H04L63/0421G06F21/6263H04L63/1475
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,483,294
App. No.
17/083,290
Granted
Oct 25, 2022
Kind
B2
Abstract

The invention described herein is directed to methods and systems for protecting network trace data. Network traces are used for network management, packet classification, traffic engineering, tracking user behavior, identifying user behavior, analyzing network hierarchy, maintaining network security, and classifying packet flows. In some embodiments, network trace data is protected by subjecting network trace data to data anonymization using an anonymization algorithm that simultaneously provides sufficient privacy to accommodate the organization need of the network trace data owner, provides acceptable data utility to accommodate management and/or network investigative needs, and provides efficient data analysis, at the same time.

Claims (14)

1. A computer-implemented method, comprising:

using differential privacy to anonymize network traces comprising the following steps:

(i) implementing a prefix-preserving technique to anonymize IP addresses of network traffic data, said prefix-preserving technique comprising permuting n leading digits as a network part, and for remaining digits clustering addresses into K clusters as a host part; and randomizing addresses within each of said K clusters;

(ii) implementing a per class differential privacy mechanism comprising conditional privacy measuring privacy of anonymized traffic data, wherein said measuring depends on mutual information between raw and anonymized records at a certain confidence level, wherein information loss is related to a mismatch amount among records before and after, wherein conditional privacy is based on differential entropy of a random variable, wherein the differential entropy of A given B=b is

h ( A|B )=∫ Ω A,B f A,B ( a,b )log 2 f A|B=b ( a ) da db   (1)

where A is a random variable that describes the data, and B is a variable that gives information on A, wherein Q _(A,B) identifies a domain of A and B, wherein average conditional privacy of A given B is

Π( A|B )=2 h(A|B)   (2)

wherein if D_i is an attribute value of the original data and D_i{circumflex over ( )}′ is the value after anonymization, then conditional privacy for anonymizing the attribute is

2 h(D i |D i ′) where h ( D i |D i ′)

is the conditional entropy of the original data given the anonymized data, and conditional privacy is calculated and averaged over all attributes;

(iii) utilizing differential privacy in a condensation method comprising clustering records based on features of network trace data, partitioning said network trace data into three clusters, wherein each cluster has packets or flows with similar features, and computing mean values of these features and adding Laplace noise to the mean values to obtain perturbed mean values, and replacing said mean values with said perturbed mean values;

wherein the method does not add any burden to a data analyser, and wherein said Data analyser analyzes network traffic data without modification;

wherein the method is performed on a computing device having memory and a hardware processor, and programming instructions saved to the memory and executable on the hardware processor for performing the steps to effect the methods steps.

2. A computer-implemented system for performing the methods herein, comprising: a computing device having a memory and a hardware processor and program instructions saved to the memory and executable by the processor for running an application configured to perform the method steps of claim 1 .

Assignments (2)
CONFIRMATORY LICENSE Recorded Aug 21, 2025
From: ANONITECH
To: U.S. DEPARTMENT OF ENERGY
Reel/Frame 072502/0717 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2022
From: AL EROUD, AHMED; CHEN, ZHIYUAN; KARABATIS, GEORGE; YANG, FAN
To: UNIVERSITY OF MARYLAND, BALTIMORE COUNTY
Reel/Frame 061060/0717 →
Continuity (2)
Provisional Application 62892726 · Aug 28, 2019
Related Publication 20210336938A1 · Oct 28, 2021
Cited By (2)
US 12,413,566 US 12,591,708