Privacy Principles for Sharing Cyber Security Data

IEEE Symposium on Security and Privacy Workshops(2015)

引用 48|浏览55
暂无评分
摘要
Sharing cyber security data across organizational boundaries brings both privacy risks in the exposure of personal information and data, and organizational risk in disclosing internal information. These risks occur as information leaks in network traffic or logs, and also in queries made across organizations. They are also complicated by the trade-offs in privacy preservation and utility present in anonymization to manage disclosure. In this paper, we define three principles that guide sharing security information across organizations: Least Disclosure, Qualitative Evaluation, and Forward Progress. We then discuss engineering approaches that apply these principles to a distributed security system. Application of these principles can reduce the risk of data exposure and help manage trust requirements for data sharing, helping to meet our goal of balancing privacy, organizational risk, and the ability to better respond to security with shared information.
更多
查看译文
关键词
data sharing,cyber security,least disclosure,qualitative evaluation,forward progress,data confinement,minimal requisite fidelity,poker queries,moderated queries,privacy principles
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要