Balancing the needs of a data analyst with the privacy needs of a data provider is a key issue when data is sanitized. This work treats both the requirements of the analyst and the privacy expectations as policies, and composes the two policies to detect conflicts. The result can be applied to an intermediate data representation to sanitize the relevant parts of the data. We conclude that this method has promise, but more work is needed to determine its effectiveness and limits.
Citation:
Matt Bishop, Bhume Bhumiratana, Rick Crawford, Karl Levitt, "How to Sanitize Data," wetice, pp.217-222, 13th IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE'04), 2004