A Composite Privacy Leakage Indicator.

Saved in:
Bibliographic Details
Title: A Composite Privacy Leakage Indicator.
Authors: Ulltveit-Moe, Nils1 nils.ulltveit-moe@uia.no, Oleshchuk, Vladimir1 vladimir.oleshchuk@uia.no
Source: Wireless Personal Communications. Dec2011, Vol. 61 Issue 3, p511-526. 16p.
Subjects: Computer network security software, Entropy (Information theory), Intrusion detection systems (Computer security), Computer security software, Data encryption, Wireless sensor networks
Abstract: This paper proposes a Subjective Logic based composite privacy leakage metric that both takes into account the amount of information leakage and also that information with high entropy in some cases may be considered encrypted. It is furthermore shown both analytically and experimentally that Min-entropy is considered better than Shannon, Rényi or Max entropy for identifying encrypted content for the composite metric. This is in particular useful for implementing privacy-enhanced Intrusion Detection Systems (IDS), where sampled encrypted traffic can be considered to have low risk of revealing sensitive information. The combined metric can be used in a Policy Enforcement Point that acts as a proxy/anonymiser in order to to reduce the leakage of private or sensitive information from the IDS sensors to an outsourced Managed Security Service provider. Although the composite privacy indicator is IDS specific, the authorisation architecture is general, and may also be useful for anonymising or pseusonymising sensitive information from or to other types of sensors that need to be exposed to the Internet. The solution is based on the eXtensible Access Control Markup Language policy language extended with support for Subjective Logic, in order to provide a method for expressing fine-grained access control policies that are based on uncertain evidences. [ABSTRACT FROM AUTHOR]
Copyright of Wireless Personal Communications is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 67105292
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: A Composite Privacy Leakage Indicator.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Ulltveit-Moe%2C+Nils%22">Ulltveit-Moe, Nils</searchLink><relatesTo>1</relatesTo><i> nils.ulltveit-moe@uia.no</i><br /><searchLink fieldCode="AR" term="%22Oleshchuk%2C+Vladimir%22">Oleshchuk, Vladimir</searchLink><relatesTo>1</relatesTo><i> vladimir.oleshchuk@uia.no</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Wireless+Personal+Communications%22">Wireless Personal Communications</searchLink>. Dec2011, Vol. 61 Issue 3, p511-526. 16p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Computer+network+security+software%22">Computer network security software</searchLink><br /><searchLink fieldCode="DE" term="%22Entropy+%28Information+theory%29%22">Entropy (Information theory)</searchLink><br /><searchLink fieldCode="DE" term="%22Intrusion+detection+systems+%28Computer+security%29%22">Intrusion detection systems (Computer security)</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security+software%22">Computer security software</searchLink><br /><searchLink fieldCode="DE" term="%22Data+encryption%22">Data encryption</searchLink><br /><searchLink fieldCode="DE" term="%22Wireless+sensor+networks%22">Wireless sensor networks</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: This paper proposes a Subjective Logic based composite privacy leakage metric that both takes into account the amount of information leakage and also that information with high entropy in some cases may be considered encrypted. It is furthermore shown both analytically and experimentally that Min-entropy is considered better than Shannon, Rényi or Max entropy for identifying encrypted content for the composite metric. This is in particular useful for implementing privacy-enhanced Intrusion Detection Systems (IDS), where sampled encrypted traffic can be considered to have low risk of revealing sensitive information. The combined metric can be used in a Policy Enforcement Point that acts as a proxy/anonymiser in order to to reduce the leakage of private or sensitive information from the IDS sensors to an outsourced Managed Security Service provider. Although the composite privacy indicator is IDS specific, the authorisation architecture is general, and may also be useful for anonymising or pseusonymising sensitive information from or to other types of sensors that need to be exposed to the Internet. The solution is based on the eXtensible Access Control Markup Language policy language extended with support for Subjective Logic, in order to provide a method for expressing fine-grained access control policies that are based on uncertain evidences. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Wireless Personal Communications is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=67105292
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s11277-011-0383-7
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 16
        StartPage: 511
    Subjects:
      – SubjectFull: Computer network security software
        Type: general
      – SubjectFull: Entropy (Information theory)
        Type: general
      – SubjectFull: Intrusion detection systems (Computer security)
        Type: general
      – SubjectFull: Computer security software
        Type: general
      – SubjectFull: Data encryption
        Type: general
      – SubjectFull: Wireless sensor networks
        Type: general
    Titles:
      – TitleFull: A Composite Privacy Leakage Indicator.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Ulltveit-Moe, Nils
      – PersonEntity:
          Name:
            NameFull: Oleshchuk, Vladimir
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 12
              Text: Dec2011
              Type: published
              Y: 2011
          Identifiers:
            – Type: issn-print
              Value: 09296212
          Numbering:
            – Type: volume
              Value: 61
            – Type: issue
              Value: 3
          Titles:
            – TitleFull: Wireless Personal Communications
              Type: main
ResultId 1