Vis enkel innførsel

dc.contributor.authorUlltveit-Moe, Nils
dc.date.accessioned2014-10-27T08:55:24Z
dc.date.available2014-10-27T08:55:24Z
dc.date.issued2014
dc.identifier.citationUlltveit-Moe, N. (2014). A roadmap towards improving managed security services from a privacy perspective. Ethics and Information Technology, 16, 227-240. doi: 10.1007/s10676-014-9348-3nb_NO
dc.identifier.issn1388-1957
dc.identifier.urihttp://hdl.handle.net/11250/224559
dc.descriptionPublished version of an article in the journal: Ethics and Information Technology. Also available from the publisher at: http://dx.doi.org/10.1007/s10676-014-9348-3nb_NO
dc.description.abstractThis paper proposes a roadmap for how privacy leakages from outsourced managed security services using intrusion detection systems can be controlled. The paper first analyses the risk of leaking private or confidential information from signature-based intrusion detection systems. It then discusses how the situation can be improved by developing adequate privacy enforcement methods and privacy leakage metrics in order to control and reduce the leakage of private and confidential information over time. Such metrics should allow for quantifying how much information that is leaking, where these information leakages are, as well as showing what these leakages mean. This includes adding enforcement mechanisms ensuring that operation on sensitive information is transparent and auditable. The data controller or external quality assurance organisations can then verify or certify that the security operation operates in a privacy friendly manner. The roadmap furthermore outlines how privacy-enhanced intrusion detection systems should be implemented by initially providing privacy-enhanced alarm handling and then gradually extending support for privacy enhancing operation to other areas like digital forensics, exchange of threat information and big data analytics based attack detection.nb_NO
dc.language.isoengnb_NO
dc.publisherSpringernb_NO
dc.subjectsecuritynb_NO
dc.subjectprivacynb_NO
dc.subjectoutsourcingnb_NO
dc.subjectintrusion detection and prevention systemsnb_NO
dc.subjectmanaged security servicesnb_NO
dc.subjectethical awarenessnb_NO
dc.titleA roadmap towards improving managed security services from a privacy perspectivenb_NO
dc.typeJournal articlenb_NO
dc.typePeer reviewednb_NO
dc.subject.nsiVDP::Mathematics and natural science: 400::Information and communication science: 420::Security and vulnerability: 424nb_NO
dc.source.pagenumber227-240nb_NO
dc.source.volume16nb_NO
dc.source.journalEthics and Information Technologynb_NO
dc.identifier.doi10.1007/s10676-014-9348-3


Tilhørende fil(er)

Thumbnail
Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel