• Aucun résultat trouvé

Monitoring accountability policies with AccMon framework

N/A
N/A
Protected

Academic year: 2021

Partager "Monitoring accountability policies with AccMon framework"

Copied!
2
0
0

Texte intégral

(1)

HAL Id: hal-01332040

https://hal.inria.fr/hal-01332040

Submitted on 15 Jun 2016

HAL is a multi-disciplinary open access

archive for the deposit and dissemination of sci-entific research documents, whether they are pub-lished or not. The documents may come from teaching and research institutions in France or abroad, or from public or private research centers.

L’archive ouverte pluridisciplinaire HAL, est destinée au dépôt et à la diffusion de documents scientifiques de niveau recherche, publiés ou non, émanant des établissements d’enseignement et de recherche français ou étrangers, des laboratoires publics ou privés.

Distributed under a Creative Commons Attribution - NonCommercial - NoDerivatives| 4.0 International License

Monitoring accountability policies with AccMon framework

Walid Benghabrit, Hervé Grall, Jean-Claude Royer

To cite this version:

Walid Benghabrit, Hervé Grall, Jean-Claude Royer. Monitoring accountability policies with AccMon framework. GDR-GPL, Jun 2016, Besançon, France. �hal-01332040�

(2)

SPECIALITY Computer Science

LABORATORY Inria, LINA

TEAM ASCOLA Research Group

LOCATION Mines Nantes - France

<first name>.<last name>@mines-nantes.fr

Director: Pr. Jean-Claude Royer

Supervisor: A/Prof. HervE Grall

IDENTITY

PhD Stu

dent

Walid Benghabrit

Monitoring

accountability

policies with

AccMon framework

∀ x:Human. watch(x)

https://github.com/hkff/AccLab https://github.com/hkff/fodtlmon

Take the control of your data

and care about your privacy,

it's already too late...

LOADING...

https://github.com/hkff/AccMon

- Inter

connec

ted syst

ems with

many

differ

ent techn

ologies which implies

many s

ecurity br

eaches

.

- Your per

sonal infor

mation ar

e already

on th

e cloud!

How to ensure that the privacy policy is respected? Distribution makes systems harder to monitor

There is NO perfect security

(1) We define what, when and how we log.

(2) We write the property to monitor in FODTL3*.

(3) We watch the running system.

(4) We audit the system when violations occurs. (5) We decide if the violation is legit or not and we trigger the remediation monitor if any.

OS <---- Sync vec tor ----> --- ---| AccMon | --- --- ---| Applications | --- --- ---| Services | --- --- ---| Hardwar e | --- --- --- ---| | | | | | | | | | | | | | --- --- --- ---| Web App ---| --- --- ---| Database | --- ---<-> | | <--- ---> | | |--> | | |--> --- ----| Machine | --- --- ----| Machine | ---

--- Accoun

tability

:

Beyond

security to pr

eserve pr

ivacy

- Monitorin

g:

Flexible and e

xtensible fra

mework

- Distribut

ed temporal logic:

Formal veri

fication over

distributed

system

* Three-valued F irst Or der Distribu ted Linear T emporal L ogic ---| Controls ---| ---| Logging ---| ---| Plugins ---| ---| Monitors ---| ---Violations Audits | | | <---> <---> ψ ::= true | false | ¬ψ | ψ ∨ ψ | ψ ∧ ψ | φ (propositional) | ∃x.ψ | ∀x.ψ (first or der) | X ψ | ψ U ψ | ψ R ψ | G ψ | F ψ (temporal) | @ p ψ (distribut ion) φ ::= P t ∗ (predicates) Monitoring t echnic: P rogression (F ormula r ewriting) eval(ψ) = T rue | False | Un known root@root:~$ man AccMon - Centralized / Distributed monitoring - Posteriori / Realtime cont rol

- Extensible framewor

k

Manual page A

ccMon (END)

(press h for help o

r q to quit)

Classical security controls Extensible logging module

Interconnection with external components Monitor with its violations and audits reports

AccMon internal architecture

- Automat

ed audit/

remediation

(Deeplear

ning.

Ethical problem? Comput

ers ta

cking human

decisions. ..)

- Usability

(Improve logical for

mula wr iting to n on specialists ) - Monitorin g: protect pr

ivacy by violating you

r privac y?

(Nothing

is good or bad, it'

s all about

how you u

se it...)

Références

Documents relatifs

Later in the clinical course, measurement of newly established indicators of erythropoiesis disclosed in 2 patients with persistent anemia inappropriately low

Households’ livelihood and adaptive capacity in peri- urban interfaces : A case study on the city of Khon Kaen, Thailand.. Architecture,

3 Assez logiquement, cette double caractéristique se retrouve également chez la plupart des hommes peuplant la maison d’arrêt étudiée. 111-113) qu’est la surreprésentation

Et si, d’un côté, nous avons chez Carrier des contes plus construits, plus « littéraires », tendant vers la nouvelle (le titre le dit : jolis deuils. L’auteur fait d’une

la RCP n’est pas forcément utilisée comme elle devrait l’être, c'est-à-dire un lieu de coordination et de concertation mais elle peut être utilisée par certains comme un lieu

The change of sound attenuation at the separation line between the two zones, to- gether with the sound attenuation slopes, are equally well predicted by the room-acoustic diffusion

Si certains travaux ont abordé le sujet des dermatoses à l’officine sur un plan théorique, aucun n’a concerné, à notre connaissance, les demandes d’avis

Using the Fo¨rster formulation of FRET and combining the PM3 calculations of the dipole moments of the aromatic portions of the chromophores, docking process via BiGGER software,