Policy auditing over incomplete logs: theory, implementation and applications

Policy auditing over incomplete logs: theory, implementation and applications
复制标题

不完整日志的策略审计:理论、实现和应用

DOI:
--
复制
发表时间:
2011
期刊:
Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Anupam Datta
Anupam Datta
中科院分区:
--
文献类型:
--
作者:
D. Garg;Limin Jia;Anupam Datta

文献摘要

被引文献

相似文献

我们介绍了一种算法的设计,实施和评估,该算法检查审核日志是否符合隐私和安全策略。我们命名的减少算法解决了合规性检查中出现的两个基本挑战。首先,为了适用于现实的策略,减少对在一阶逻辑中表达的策略进行操作,该逻辑允许对无限域进行限制定量。我们以逻辑编程的想法为基础,以确定量化公式的受限形式。逻辑尤其可以表达HIPAA隐私规则的所有84个与披露有关的条款,该子句涉及对包含个人信息的无限消息集进行量化。其次,由于审核日志本质上是不完整的(它们可能不包含足够的信息来确定是否违反策略),请迭代地减少收益:在每次迭代中,它可以证明在当前日志中检查了尽可能多的策略仅当日志扩展附加信息时才能检查的剩余策略。我们证明正确性,终止,时间和空间复杂性可减少。我们使用两个策略结构指导的数据库索引来实施并优化基本实现。该实现用于检查模拟审核日志以符合HIPAA隐私规则。我们的实验结果表明,该算法足够快,可以在实践中使用。
We present the design, implementation and evaluation of an algorithm that checks audit logs for compliance with privacy and security policies. The algorithm, which we name reduce, addresses two fundamental challenges in compliance checking that arise in practice. First, in order to be applicable to realistic policies, reduce operates on policies expressed in a first-order logic that allows restricted quantification over infinite domains. We build on ideas from logic programming to identify the restricted form of quantified formulas. The logic can, in particular, express all 84 disclosure-related clauses of the HIPAA Privacy Rule, which involve quantification over the infinite set of messages containing personal information. Second, since audit logs are inherently incomplete (they may not contain sufficient information to determine whether a policy is violated or not), reduce proceeds iteratively: in each iteration, it provably checks as much of the policy as possible over the current log and outputs a residual policy that can only be checked when the log is extended with additional information. We prove correctness, termination, time and space complexity results for reduce. We implement reduce and optimize the base implementation using two heuristics for database indexing that are guided by the syntactic structure of policies. The implementation is used to check simulated audit logs for compliance with the HIPAA Privacy Rule. Our experimental results demonstrate that the algorithm is fast enough to be used in practice.