Feeds

Microsoft boffins: Now even LAWYERS can grok Bing code's privacy compliance

Non-techies can get code fixed for privacy laws in real time. So sez Redmond

Choosing a cloud hosting partner with confidence

Boffins at Microsoft Research have devised a way to automatically check code for compliance with privacy laws – and, according to Redmond, it's so simple that even non-techies can use it successfully.

Microsoft Research (MSR) has developed a programming language called Legalease, to be used together with its data inventory engine, Grok, which it claims can comb millions of lines of constantly changing code and check that it complies with rules on privacy.

Legalease is intended for use by non-programming types to specify restrictions on how data is handled. One of the main drivers behind Legalease's development was that software developers and those setting companies’ privacy policies don’t share a common language.

MSR says that more than 20 per cent of the code in Bing changes on a daily basis, with changes made by thousands of programmers. Changes in code might affect how data is used or who views it, potentially violating company, government or regulatory privacy policies.

Keeping tabs on changes in very large systems, like the Bing search engine, using manual audits is difficult. According to MSR automated testing is the best way to verify compliance with privacy rules and laws on the massive scale demanded in environments like Bing.

Legalease uses allow/deny rules, with exceptions. This reflects privacy policy frameworks like the US Health Insurance Portability and Accountability Act (HIPPA).

Grok

Grok, meanwhile, annotates existing code using a system that cross-references information from different sources, based on varying levels of confidence.

According to Microsoft, pattern-matching to column names across a database results in a low-confidence score, while annotations made manually by developers are deemed to be more trustworthy and thus get a high-confidence score.

MSR says it developed Grok for use on Bing but found writing suitable polices hard – and this was what led to Legalese. Both were tested on Bing and are now running on the data analytics pipeline of Microsoft's search engine.

MSR presented Legalese and Grok at the 35th IEEE Symposium on Security and Privacy in San Jose, California, this week. Redmond claims a group of non-coders took less than five minutes to learn how to use Legalease and just 15 minutes to code nine Bing policy clauses on the use of user information.

Saikat Guha, a researcher at Microsoft, in a statement called Legalease “the final piece of the automated privacy compliance jigsaw puzzle."

You can read more on the Microsoft Research site here. ®

Internet Security Threat Report 2014

More from The Register

next story
Preview redux: Microsoft ships new Windows 10 build with 7,000 changes
Latest bleeding-edge bits borrow Action Center from Windows Phone
Google opens Inbox – email for people too thick to handle email
Print this article out and give it to someone tech-y if you get stuck
Microsoft promises Windows 10 will mean two-factor auth for all
Sneak peek at security features Redmond's baking into new OS
UNIX greybeards threaten Debian fork over systemd plan
'Veteran Unix Admins' fear desktop emphasis is betraying open source
Entity Framework goes 'code first' as Microsoft pulls visual design tool
Visual Studio database diagramming's out the window
Google+ goes TITSUP. But WHO knew? How long? Anyone ... Hello ...
Wobbly Gmail, Contacts, Calendar on the other hand ...
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.