VACCINE: Using Contextual Integrity For Data Leakage Detection

VACCINE: Using Contextual Integrity For Data Leakage Detection
复制标题

疫苗:使用上下文完整性进行数据泄漏检测

DOI:
10.1145/3308558.3313655
复制
发表时间:
2019
期刊:
Proceedings of the 2019 World Wide Web Conference
影响因子:
--
通讯作者:
Mittal, Prateek
Mittal, Prateek
中科院分区:
--
文献类型:
--
作者:
Shvartzshnaider, Yan;Pavlinovic, Zvonimir;Balashankar, Ananth;Wies, Thomas;Subramanian, Lakshminarayanan;Nissenbaum, Helen;Mittal, Prateek

文献摘要

参考文献

被引文献

相似文献

现代企业依靠数据泄漏防护(DLP)系统来实施隐私策略,以防止敏感信息意外流向未经授权的实体。然而,这些系统的操作基于规则集,这些规则集仅限于句法分析,因此完全忽略了参与信息交换的参与者之间的语义关系。出于类似的原因,这些系统不能强制执行复杂的隐私政策,需要时间推理的事件,以前已经发生的。为了解决这些限制,我们提倡一种新的设计方法DLP系统的上下文完整性(CI)的概念为中心。我们使用CI框架抽象到正式定义的信息流,隐私政策描述序列的可接受的流的真实世界的通信交流。CI允许我们解耦(1)从信息交换中提取流的语法,以及(2)对这些流执行隐私策略。我们将这种方法应用于构建VACCINE,一个用于电子邮件的DLP审计系统。VACCINE使用自然语言处理中最先进的技术从电子邮件文本中提取流。它还提供了一种用于描述隐私策略的声明性语言。这些策略会自动编译为系统用于检测数据泄漏的操作规则。我们评估了安然电子邮件语料库上的疫苗,并表明它在DLP系统可以执行的政策的表现力以及检测数据泄漏的精度方面都优于最先进的技术。
Modern enterprises rely on Data Leakage Prevention (DLP) systems to enforce privacy policies that prevent unintentional flow of sensitive information to unauthorized entities. However, these systems operate based on rule sets that are limited to syntactic analysis and therefore completely ignore the semantic relationships between participants involved in the information exchanges. For similar reasons, these systems cannot enforce complex privacy policies that require temporal reasoning about events that have previously occurred.To address these limitations, we advocate a new design methodology for DLP systems centered on the notion of Contextual Integrity (CI). We use the CI framework to abstract real-world communication exchanges into formally defined information flows where privacy policies describe sequences of admissible flows. CI allows us to decouple (1) the syntactic extraction of flows from information exchanges, and (2) the enforcement of privacy policies on these flows. We applied this approach to built VACCINE, a DLP auditing system for emails. VACCINE uses state-of-the-art techniques in natural language processing to extract flows from email text. It also provides a declarative language for describing privacy policies. These policies are automatically compiled to operational rules that the system uses for detecting data leakages. We evaluated VACCINE on the Enron email corpus and show that it improves over the state of the art both in terms of the expressivity of the policies that DLP systems can enforce as well as its precision in detecting data leakages.
RECIPE:将开放域问答应用于隐私政策
DOI: 10.18653/v1/w18-2608
发表时间: 2018
期刊: 2016 IEEE 24th International Requirements Engineering Conference Workshops (REW)
影响因子: --
作者:
Yan Shvartzshanider;Ananth Balashankar;Thomas Wies;L. Subramanian
通讯作者: L. Subramanian
可兑现的隐私承诺:适用于 HIPAA 隐私规则的策略分析方法
DOI: --
发表时间: 2013
期刊: ACM Symposium on Access Control Models and Technologies
影响因子: --
作者:
Omar Chowdhury;Andreas Gampe;Jianwei Niu;J. Ronne;Jared Bennatt;Anupam Datta;Limin Jia;W. Winsborough
通讯作者: W. Winsborough
检查站
DOI: --
发表时间: 2018
期刊: Oxford Scholarship Online
影响因子: --
作者:
Jim Sykes
通讯作者: Jim Sykes
对语言设计者的提醒
DOI: --
发表时间: 1976
期刊: SIGP
影响因子: --
作者:
Frederick S. Richard;H. Ledgard
通讯作者: H. Ledgard
用于隐私策略运行时监控的时间模式检查
DOI: --
发表时间: 2014
期刊: International Conference on Computer Aided Verification
影响因子: --
作者:
Omar Chowdhury;Limin Jia;D. Garg;Anupam Datta
通讯作者: Anupam Datta