DocumentCode :
2397332
Title :
Securing information flows: A quantitative risk analysis approach
Author :
Srivatsa, Mudhakar ; Rohatgi, Pankaj ; Balfe, Shane
Author_Institution :
T.J. Watson Res. Center, IBM, Yorktown Heights, NY
fYear :
2008
fDate :
16-19 Nov. 2008
Firstpage :
1
Lastpage :
7
Abstract :
Risk-based information trading systems have recently emerged as a new paradigm for enabling information sharing in dynamic environments. Such systems build an information trading market whose commodity is information (quantized into objects) and whose currency is monetized evaluated risk. In these trading systems, risk is calculated by the information seller (and consequently charged to the information buyer) as a function of the value of the object and an information buyerpsilas propensity to divulge shared information (based on observed past behavior). Whilst standard techniques exist for evaluating the value of an object, determining the propensity of a buyer to leak information is somewhat more problematic. Ostensibly, a seller could rely on static pre-assigned credentials of the buyer, however, such credentials only provide a clue as to the buyerpsilas ldquotrustworthinessrdquo at the time of credential issuance and gives no indication of post-issuance behavior. In this paper, we propose the use of a information leakage monitoring subsystem as part of a larger risk trading system to detect information leakage. We propose a framework for the design of such a subsystem and identify the fundamental tradeoffs between maximum information leakage rates, delays in leakage detection, buyer budgetary constraints and inherent errors in the monitoring subsystem.
Keywords :
information dissemination; risk analysis; security of data; credential issuance; information flows; information leakage monitoring subsystem; quantitative risk analysis; risk-based information trading systems; Cost accounting; Delay; Information security; Leak detection; Military computing; Monitoring; Protection; Risk analysis; Risk management; Terrorism;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Military Communications Conference, 2008. MILCOM 2008. IEEE
Conference_Location :
San Diego, CA
Print_ISBN :
978-1-4244-2676-8
Electronic_ISBN :
978-1-4244-2677-5
Type :
conf
DOI :
10.1109/MILCOM.2008.4753319
Filename :
4753319
Link To Document :
بازگشت