The VACCINE Framework for Building DLP Systems
Yan Shvartzshnaider, Zvonimir Pavlinovic, Thomas Wies,, Lakshminarayanan Subramanian, Prateek Mittal, Helen Nissenbaum

TL;DR
VACCINE is a modular framework that leverages contextual integrity and verification techniques to create adaptable, correct, and reusable data leakage prevention rules across heterogeneous communication protocols.
Contribution
The paper introduces VACCINE, a novel framework combining contextual integrity theory and programming language verification to enhance DLP systems' flexibility and correctness.
Findings
VACCINE effectively enforces privacy policies in heterogeneous environments.
It provides correctness guarantees for privacy rule enforcement.
The framework scales to large enterprise settings with thousands of actors.
Abstract
Conventional Data Leakage Prevention (DLP) systems suffer from the following major drawback: Privacy policies that define what constitutes data leakage cannot be seamlessly defined and enforced across heterogeneous forms of communication. Administrators have the dual burden of: (1) manually self-interpreting policies from handbooks to specify rules (which is error-prone); (2) extracting relevant information flows from heterogeneous communication protocols and enforcing policies to determine which flows should be admissible. To address these issues, we present the Verifiable and ACtionable Contextual Integrity Norms Engine (VACCINE), a framework for building adaptable and modular DLP systems. VACCINE relies on (1) the theory of contextual integrity to provide an abstraction layer suitable for specifying reusable protocol-agnostic leakage prevention rules and (2) programming language…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAccess Control and Trust · Security and Verification in Computing · Cloud Data Security Solutions
