首页> 外文会议>International Conference in Software Engineering Research and Innovation >Towards an Efficient Log Data Protection in Software Systems through Data Minimization and Anonymization
【24h】

Towards an Efficient Log Data Protection in Software Systems through Data Minimization and Anonymization

机译:通过数据最小化和匿名化实现软件系统中的有效日志数据保护

获取原文

摘要

IT infrastructures of companies generate large amounts of log data every day. These logs are typically analyzed by software engineers to gain insights about activities occurring within a company (e.g., to debug issues exhibited by the production systems). To facilitate this process, log data management is often outsourced to cloud providers. However, logs may contain information that is sensitive by nature and considered personal identifiable under most of the new privacy protection laws, such as the European General Data Protection Regulation (GDPR). To ensure that companies do not violate regulatory compliance, they must adopt, in their software systems, appropriate data protection measures. Such privacy protection laws also promote the use of anonymization techniques as possible mechanisms to operationalize data protection. However, companies struggle to put anonymization in practice due to the lack of integrated, intuitive, and easy-to-use tools that accommodate effectively with their log management systems. In this paper, we propose an automatic approach (SafeLog) to filter out information and anonymize log streams to safeguard the confidentiality of sensitive data and prevent its exposure and misuse from third parties. Our results show that atomic anonymization operations can be effectively applied to log streams to preserve the confidentiality of information, while still allowing to conduct different types of analysis tasks such as users behavior, and anomaly detection. Our approach also reduces the amount of data sent to cloud vendors, hence decreasing the financial costs and the risk of overexposing information.
机译:公司的IT基础架构每天都会生成大量日志数据。这些日志通常由软件工程师进行分析,以获取有关公司内部活动的见解(例如,调试生产系统出现的问题)。为了促进此过程,日志数据管理通常外包给云提供商。但是,日志可能包含本质上敏感的信息,并且在大多数新的隐私保护法律(例如欧洲通用数据保护条例(GDPR))下被认为是个人可识别的信息。为确保公司不违反法规遵从性,他们必须在其软件系统中采取适当的数据保护措施。此类隐私保护法还促进使用匿名化技术作为实现数据保护的可能机制。但是,由于缺乏集成,直观且易于使用的工具来有效地适应其日志管理系统,因此公司难以将匿名化付诸实践。在本文中,我们提出了一种自动方法(SafeLog),用于过滤信息并匿名化日志流,以保护敏感数据的机密性,并防止其泄露和被第三方滥用。我们的结果表明,原子匿名操作可以有效地应用于日志流,以保护信息的机密性,同时仍然允许执行不同类型的分析任务,例如用户行为和异常检测。我们的方法还减少了发送给云供应商的数据量,从而降低了财务成本和信息过度暴露的风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号