A configurable anonymisation approach for network flow data: Balancing utility and privacy
Liam Daly Manocchio, Siamak Layeghy, David Gwynne, Marius Portmann · Computers & Electrical Engineering · 2024
This paper introduces a novel anonymisation scheme that enables a configurable trade off between the utility of the anonymised network data for Machine Learning (ML)-based Network Intrusion Detection Systems (NIDS) and the level of privacy preservation. The method enhances both the utility and the level of privacy protection of the anonymised network data containing personal information. Current approaches focus on privacy preservation, overlooking the importance of assessing the suitability of anonymised data for ML-based NIDS. In contrast, our proposed method not only strengthens privacy requirements but also generates datasets that significantly enhance the utility for machine learning algorithms and applications. To evaluate the effectiveness of our method, we conducted a thorough assessment using a real-world network dataset in NetFlow format. Comparing the anonymisation performance of our scheme with state-of-the-art techniques, we observed a substantial improvement of up to 50% in terms of reduced information leakage. To facilitate accessibility and evaluation, we are providing the research community with the code for our anonymisation scheme. This open access approach aims to encourage further exploration and validation of our proposed method in diverse research settings.