• DocumentCode
    61438
  • Title

    Privacy-Preserving Detection of Sensitive Data Exposure

  • Author

    Xiaokui Shu ; Danfeng Yao ; Bertino, Elisa

  • Author_Institution
    Dept. of Comput. Sci., Virginia Tech, Blacksburg, VA, USA
  • Volume
    10
  • Issue
    5
  • fYear
    2015
  • fDate
    May-15
  • Firstpage
    1092
  • Lastpage
    1103
  • Abstract
    Statistics from security firms, research institutions and government organizations show that the number of data-leak instances have grown rapidly in recent years. Among various data-leak cases, human mistakes are one of the main causes of data loss. There exist solutions detecting inadvertent sensitive data leaks caused by human mistakes and to provide alerts for organizations. A common approach is to screen content in storage and transmission for exposed sensitive information. Such an approach usually requires the detection operation to be conducted in secrecy. However, this secrecy requirement is challenging to satisfy in practice, as detection servers may be compromised or outsourced. In this paper, we present a privacy-preserving data-leak detection (DLD) solution to solve the issue where a special set of sensitive data digests is used in detection. The advantage of our method is that it enables the data owner to safely delegate the detection operation to a semihonest provider without revealing the sensitive data to the provider. We describe how Internet service providers can offer their customers DLD as an add-on service with strong privacy guarantees. The evaluation results show that our method can support accurate detection with very small number of false alarms under various data-leak scenarios.
  • Keywords
    Internet; computer network security; data privacy; DLD; Internet service provider; add-on service; data leak detection; privacy preserving detection; sensitive data exposure; Data models; Data privacy; Electronic mail; Organizations; Privacy; Protocols; Security; Data leak; collection intersection; network security; privacy;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2015.2398363
  • Filename
    7038200