首页> 外文会议>IEEE International Symposium on High-Assurance Systems Engineering >Transforming Privacy Policies to Auditing Specifications
【24h】

Transforming Privacy Policies to Auditing Specifications

机译:将隐私政策转换为审计规范

获取原文

摘要

With more and more personal data being collected and stored by service providers, there is an increasing need to ensure that their usage is compliant with privacy regulations. We consider the specific scenario where policies are defined in metric temporal logic and audited against the database usage logs. Previous works have shown that this can indeed be achieved in an efficient manner for a very expressive set of policies. One of the main ingredients of such an auditing process is the availability of sufficient database logs. Currently, it is a manual process to first determine the logs needed, and then come up with the necessary auditing specifications to generate them. This is not only a time consuming process but can be erroneous as well, leading to either insufficient or redundant logging. Logging in general is costly as it is an overhead on the real-time database performance, and hence redundant logging is not an alternative either. Our contribution in this work is to streamline the log generation process by deriving the auditing specifications directly from the policies to be audited. We also show how the required logging can be minimized based on the temporal constraints specified in the policies. Given privacy policies as input, the output of the proposed tool is the corresponding auditing specifications that can be installed directly in the databases, to produce logs that are both minimal and sufficient to audit the given policies. The tool has been implemented and tested in a real-life scenario.
机译:通过越来越多的个人数据被收集并由服务提供商存储,越来越需要确保其使用符合隐私法规。我们考虑在度量标准时间逻辑中定义策略并审核数据库使用日志的具体方案。以前的作品表明,这确实可以以有效的方式实现非常有效的一系列政策。这种审计过程的主要成分之一是有足够的数据库日志的可用性。目前,它是首先确定所需的日志的手动过程,然后提出必要的审计规范来生成它们。这不仅是耗时的过程,而且可能是错误的,导致记录不足或冗余。日志记录一般是昂贵的,因为它是实时数据库性能的开销,因此冗余日志记录也不是替代。我们在这项工作中的贡献是通过直接从审核的策略导出审计规范来简化日志生成过程。我们还展示了如何根据策略中指定的时间约束最小化所需的日志记录。给定的隐私政策作为输入,所提出的工具的输出是可以直接安装在数据库中的相应审计规范,以产生既有最小值且足以审核给定策略的日志。该工具已在现实生活场景中实现和测试。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号