• DocumentCode
    62870
  • Title

    Application-Screen Masking: A Hybrid Approach

  • Author

    Goldsteen, Abigail ; Kveler, Ksenya ; Domany, Tamar ; Gokhman, Igor ; Rozenberg, Boris ; Farkash, Ariel

  • Volume
    32
  • Issue
    4
  • fYear
    2015
  • fDate
    July-Aug. 2015
  • Firstpage
    40
  • Lastpage
    45
  • Abstract
    Large organizations often face difficult tradeoffs in balancing the need to share information with the need to safeguard sensitive data. A prominent way to deal with this tradeoff is on-the-fly screen masking of sensitive data in applications. A proposed hybrid approach for masking Web application screens combines the advantages of the context available at the presentation layer with the flexibility and low overhead of masking at the network layer. This solution can identify sensitive information in the visual context of the application screen and then automatically generate the masking rules to enforce at run time. This approach supports the creation of highly expressive masking rules, while keeping rule authoring easy and intuitive, resulting in an easy to use, effective system. This article is part of a special issue on Security and Privacy on the Web. The Web extra at https://youtu.be/4u2FLqjaIiI is a short demonstration of a proposed hybrid approach for masking Web application screens that combines the advantages of the context available at the presentation layer with the flexibility and low overhead of masking at the network layer. The second Web extra at https://youtu.be/-Hz3P_H0UnU is a full-length demonstration of a proposed hybrid approach for masking Web application screens that combines the advantages of the context available at the presentation layer with the flexibility and low overhead of masking at the network layer.
  • Keywords
    Internet; authorisation; data privacy; information management; Web application screens; application-screen masking; data privacy; data security; information sharing; network layer; presentation layer; rule authoring; sensitive data masking; Browsers; Computer security; Context modeling; HTML; Security; Software developmnet; Software engineering; Visualization; Web services; Web applications; Web apps; Web privacy; Web security; context-based rules; data masking; screen masking; software development; software engineering;
  • fLanguage
    English
  • Journal_Title
    Software, IEEE
  • Publisher
    ieee
  • ISSN
    0740-7459
  • Type

    jour

  • DOI
    10.1109/MS.2015.75
  • Filename
    7106392