首页> 外文期刊>Future generation computer systems >A policy-based containerized filter for secure information sharing in organizational environments
【24h】

A policy-based containerized filter for secure information sharing in organizational environments

机译:基于策略的集装箱式过滤器,用于组织环境中的安全信息共享

获取原文
获取原文并翻译 | 示例

摘要

In organizational environments, sensitive information is unintentionally exposed and sent to the cloud without encryption by insiders that even were previously informed about cloud risks. To mitigate the effects of this information privacy paradox, we propose the design, development and implementation of SecFilter, a security filter that enables organizations to implement security policies for information sharing. SecFilter automatically performs the following tasks: (a) intercepts files before sending them to the cloud; (b) searches for sensitive criteria in the context and content of the intercepted files by using mining techniques; (c) calculates the risk level for each identified criterion; (d) assigns a security level to each file based on the detected risk in its content and context: and (e) encrypts each file by using a multi-level security engine, based on digital envelopes from symmetric encryption, attribute-based encryption and digital signatures to guarantee the security services of confidentiality, integrity and authentication on each file at the same time that access control mechanisms are enforced before sending the secured file versions to cloud storage. A prototype of SecFilter was implemented for a real-world file sharing application that has been deployed on a private cloud. Fine-tuning of SecFilter components is described and a case study has been conducted based on document sharing of a well-known repository (MedLine corpus). The experimental evaluation revealed the feasibility and efficiency of applying a security filter to share information in organizational environments. (C) 2019 Elsevier B.V. All rights reserved.
机译:在组织环境中,敏感信息无意中公开并发送到云,而不会被内部人加密,即甚至先前通知云风险。为减轻本信息隐私悖论的影响,我们提出了Secfilter的设计,开发和实现,这是一个安全筛选器,使组织能够实施信息共享的安全策略。 secfilter自动执行以下任务:(a)在将它们发送到云之前拦截文件; (b)通过使用挖掘技术搜索截获文件的上下文和内容中的敏感标准; (c)计算每个识别的标准的风险等级; (d)基于其内容和上下文中的检测到的风险为每个文件分配安全级别:(e)通过基于来自对称加密的数字信封,基于属性的加密和基于数字信封来加密每个文件。数字签名,以保证在每个文件上的机密性,完整性和身份验证的安全服务,同时在向云存储发送安全文件版本之前强制执行访问控制机制。 Secfilter的原型是为已经部署在私有云上的实际文件共享应用程序的原型。描述了SecFilter组件的微调,并且已经基于众所周知的存储库(Medline语料库)的文档共享进行了案例研究。实验评估揭示了应用安全滤波器在组织环境中共享信息的可行性和效率。 (c)2019 Elsevier B.v.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号