Vis enkel innførsel

dc.contributor.authorUlltveit-Moe, Nils
dc.date.accessioned2014-04-28T09:01:40Z
dc.date.available2014-04-28T09:01:40Z
dc.date.issued2013
dc.identifier.isbn978-82-7117-762-1
dc.identifier.urihttp://hdl.handle.net/11250/194485
dc.descriptionDoktorgradsavhandling i informasjons- og kommunikasjonsteknologi, Universitetet i Agder, 2014nb_NO
dc.description.abstractThis PhD dissertation investigates two necessary means that are required for building privacy-enhanced network monitoring systems: a policy-based privacy or confidentiality enforcement technology; and metrics measuring leakage of private or confidential information to verify and improve these policies. The privacy enforcement mechanism is based on fine-grained access control and reversible anonymisation of XML data to limit or control access to sensitive information from the monitoring systems. The metrics can be used to support a continuous improvement process, by quantifying leakages of private or confidential information, locating where they are, and proposing how these leakages can be mitigated. The planned actions can be enforced by applying a reversible anonymisation policy, or by removing the source of the information leakages. The metrics can subsequently verify that the planned privacy enforcement scheme works as intended. Any significant deviations from the expected information leakage can be used to trigger further improvement actions. The most significant results from the dissertation are: a privacy leakage metric based on the entropy standard deviation of given data (for example IDS alarms), which measures how much sensitive information that is leaking and where these leakages occur; a proxy offering policy-based reversible anonymisation of information in XML-based web services. The solution supports multi-level security, so that only authorised stakeholders can get access to sensitive information; a methodology which combines privacy metrics with the reversible anonymisation scheme to support a continuous improvement process with reduced leakage of private or confidential information over time. This can be used to improve management of private or confidential information where managed security services have been outsourced to semi-trusted parties, for example for outsourced managed security services monitoring health institutions or critical infrastructures. The solution is based on relevant standards to ensure backwards compatibility with existing intrusion detection systems and alarm databases.nb_NO
dc.language.isoengnb_NO
dc.publisherUniversitet i Agder / University of Agdernb_NO
dc.relation.ispartofseriesDoctoral dissertations at the University of Agder;83
dc.subjectVDP::Matematikk og Naturvitenskap: 400::Informasjons- og kommunikasjonsvitenskap: 420::Sikkerhet og sårbarhet: 424nb_NO
dc.titlePrivacy-enhanced network monitoringnb_NO
dc.typeDoctoral thesisnb_NO
dc.typePeer reviewednb_NO
dc.subject.nsiVDP::Social science: 200::Economics: 210::Business: 213
dc.subject.nsiVDP::Technology: 500::Information and communication technology: 550
dc.source.pagenumberXVII, 277 p.nb_NO


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel