The objective of the 3rd ACM Workshop on Information Sharing and Collaborative Security is to advance the scientific foundations for sharing security-related data. Improving information sharing remains an important theme in the computer security community. A number of new sharing communities have been formed. Also, so called "threat intelligence" originating from open, commercial or governmental sources has by now become an important, commonly used tool for detecting and mitigating attacks in organizations. Security vendors are offering novel technologies for sharing, managing and consuming such data. The OASIS Technical Committee for Cyber Threat Intelligence (CTI) is creating a standard for structured sharing of information. This is the largest TC within OASIS attesting to the broad interest in the topic. As progress in real-life deployment of information sharing makes clear, the creation, analysis, sharing, and effective use of security data continues to raise intriguing technical problems. Addressing these problems will be critical for the ultimate success of sharing efforts and will benefit greatly from the diverse knowledge and techniques the scientific community brings. The 3rd ACM Workshop on Information Sharing and Collaborative Security (WISCS'16) brings together experts and practitioners from academia, industry, and government to present innovative research, case studies, and legal and policy issues. WISCS'16 is held in Vienna, Austria on October 24, 2016 in conjunction with the 23rd ACM Conference on Computer and Communications Security (ACM CCS 2016).
There are many realistic settings where two mutually suspicious parties need to share some specific information while keeping everything else private. Various privacy-preserving techniques (such as Private Set Intersection) have been proposed as general solutions. Based on timely real-world examples, this paper motivates the need for a new privacy tool, called Private Set Intersection with Projection (PSI-P). In it, Server has (at least) a two-attribute table and Client has a set of values. At the end of the protocol, based on all matches between Client's set and values in one (search) attribute of Server's database, Client should learn the set of elements corresponding to the second attribute, and nothing else. In particular the intersection of Client's set and the set of values in the search attribute must remain hidden. We construct several efficient (linear complexity) protocols that approximate privacy required by PSI-P and suffice in many practical scenarios. We also provide a new construction for PSI-P with full privacy, albeit it is slightly less efficient. Its key building block is a primitive called Existential Private Set Intersection (PSI-X) which yields a binary flag indicating whether the intersection of two private sets is empty or non-empty.
The mission of the 2nd ACM Workshop on Information Sharing and Collaborative Security is to advance the scientific foundations for sharing threat and security-related data among organizations. The call for better information sharing continues to be an important theme in the computer security community and with policy makers. The expectation is that sharing will significantly improve the ability of defenders to detect and mitigate attacks on their networks and systems. Several commercial offerings by security vendors that enable automated sharing have gone live and existing communities have begun to use them. Sharing of security and threat data at scale raises a number of interesting research questions, including on how to best collect, analyze and make use of these data to address important security concerns. In addition sharing raises privacy and other policy issues that need to be addressed. The 2nd ACM Workshop on Information Sharing and Collaborative Security (WISCS'15) aims to bring together experts and practitioners from academia, industry and government to present innovative research, case studies, and legal and policy issues. WISCS'15 is held in Denver, Colorado, USA on October 12, 2015 in conjunction with the 22nd ACM Conference on Computer and Communications Security (ACM CCS 2015).
This paper initiates the systematic study of the human elements of participating in an information exchange using a Threat Information Sharing Platform (TISP). Much of the most valuable information to be shared within a TISP is created or validated by human security analysts. Thus getting UX design and the human motivations for a TISP right is crucial for its success. We approach this problem from one of the primary HCI and UX methods | personas. Our results allow TISP engineers and designers to understand and articulate the value propositions as well as the obstacles of a TISP for the CSIRT (Computer Security Incident and Response Team) of an organization. Second, we crafted a set of design requirements explicitly drawn from our personas. These design requirements explicitly highlight how TISPs can be improved, or needs that should be addressed to increase their value-add and usability. Our five personas were created from eight hour long interviews as well as over 20 hours of ethnographic observation of CSIRTs and Security Operations Centers (SOCs.)
Des exemples de la presente invention concernent des alertes pour des communautes d'une plate-forme de partage d'informations de securite. Certains exemples peuvent consister a : obtenir un indicateur de securite, d'un utilisateur d'une premiere communaute d'une plate-forme de partage d'informations de securite qui permet de partager des informations de securite entre une pluralite de communautes ; integrer l'indicateur de securite dans des informations de securite basees sur la communaute, associees a la premiere communaute, le premier indicateur de securite comprenant un premier element observable ; partager le premier indicateur de securite avec la plate-forme de partage d'informations de securite ; obtenir, de la plate-forme de partage d'informations de securite, des informations relatives a des reperages du premier element observable ; et fournir une premiere alerte a la premiere communaute sur la base des informations relatives aux reperages du premier element observable.
Sharing of security related information is believed to greatly enhance the ability of organizations to defend themselves against sophisticated attacks. If one organization detects a breach the automated sharing of observed security indicators (such as IP addresses, domain names etc.) provide valuable, actionable information to others. Through analyzing shared data it seems possible to get much better insights into emerging attacks. Sharing higher level intelligence about campaigns, threat actors and mitigations is also of great interest. Both in the US and the EU there are major efforts underway to strengthen information sharing. Yet there are a number of technical and policy challenges to realizing this vision.The First ACM Workshop on Information Sharing and Collaborative Security (WISCS 2014) aims to bring together experts and practitioners from academia, industry and government to present innovative research, case studies, and legal and policy issues. WISCS 2014 is held in Scottsdale, Arizona, USA on Nov. 3, 2014 in conjunction with 21st ACM Conference on Computer and Communications Security (CCS 2014).
Regulatory compliance in areas such as privacy has become a major challenge for organizations. In large organizations there can be hundreds or thousands of projects that involve personal information. Ensuring that all those projects properly take privacy considerations into account is a complex challenge for accountable privacy management. Accountable privacy management requires that an organization makes sure that all relevant projects are in compliance and that there is evidence and assurance that this actually is the case. To date, there has been no suitable automated, scalable support for accountable privacy management; it is such a tool that the authors describe in this chapter. Specifically, they describe a privacy risk assessment and compliance tool which they are developing and rolling out within a large, global company – called HP Privacy Advisor (HP PA) – and its generalisation and extension. The authors also bring out those security, privacy, risk, and trust-related aspects they have been researching related to this work in particular.
This paper presents a mapping of enriched knowledge resources for data privacy management. An ontology, enriched through natural language techniques, is used for an integrated visualization for global inspection of heterogeneous data. The visualization helps stakeholders in exploring and maintaining a knowledge base for data privacy accountability. The integration of resources on the basis of concepts described in an enriched ontology is an aid to Knowledge Management (KM) in a dynamic domain, due to changes in laws and the corresponding system requirements.
We describe a mechanism in which context is gathered relating to service providers (SPs), this is inputted to a rule-based system, and decisions are output about the suitability of each SP, including recommended stipulations regarding their usage. It can be used tor Service-Oriented Architectures (SOAs) to determine appropriate actions that should be allowed, or in a cloud context, to help assess risk before personal information is passed on through the cloud. It is semi-automated to significantly lower the transaction costs for the selection of SPs.
This paper discusses knowledge representation for privacy and accountability issues.Use of personal information from customers is a common practice among companies and governments around the world.Knowing and applying current privacy legislation is an important requirement for IT projects.Inadequate procedures or data breaches can lead to lawsuits and loss of consumer trust for the company [1].IT project managers are mainly aware of their business goals, but not of specific required actions to assure that the project is privacy-compliant.
This poster discusses domain ontologies on the privacy field for automatic risk identification and project qualification. It presents an ontology model for describing risks as an interpretation of privacy policies contextualized in project specifications.
—Clear and consistent assessment of the various capabilities of cloud service providers (CSPs) will become an essential factor in deciding on which CSPs to use in the future, particularly as cloud service provision expands futher into more sensitive and regulated areas. This paper describes an approach that is useful in this regard. Specifically, we describe a mechanism in which context is gathered relating to CSPs; this is inputted to a rule-based system and decisions are output about the suitability of each CSP, including an analysis of privacy and security risk and recommended stipulations to be taken into account when negotiating contracts and SLAs.
This paper presents the overall problem of privacy risk assessment in the software industry and the difficulty to deal with all normative sources that regulate privacy matters. This problem encompasses the hard task of representing all the relevant information and keep it updated. Ontologies are the main mechanism for domain-specific knowledge representation in the Semantic Web context, but their manual maintenance is expensive and error-prone. Following the ontology learning trend, this paper presents an approach to automatically populate a legal ontology from legal texts through the Named Entity Recognition task and an experiment on this approach. Legal ontologies have been an active topic of research for quite a while, but on specific domains such as data privacy there is still a lack of such resources. The experiment described in this paper is run over a corpus of legal and normative documents for privacy, shows promising results and presents opportunities for the continuation of this research.
In this paper we look at the complex area of a global outsourcing delivery model among different countries and/or organizations. In this case, privacy requirements stemming from requirements of various countries of data origin need to be honoured and taken into account during the data lifecycle. We review practical privacy management challenges arising in large, global organizations and discuss technology needed to address them. As a first example we describe the design of a privacy tool built and deployed to help an organization identify and manage privacy concerns in the context of Business Process Outsourcing (BPO). As a generalization of this technology we present an automated solution for scalable, accountable privacy management.
Marco Casassa-Mont合作论文数Hewlett Packard Laboratories1