Feeds

Microsoft boffins: Now even LAWYERS can grok Bing code's privacy compliance

Non-techies can get code fixed for privacy laws in real time. So sez Redmond

Security for virtualized datacentres

Boffins at Microsoft Research have devised a way to automatically check code for compliance with privacy laws – and, according to Redmond, it's so simple that even non-techies can use it successfully.

Microsoft Research (MSR) has developed a programming language called Legalease, to be used together with its data inventory engine, Grok, which it claims can comb millions of lines of constantly changing code and check that it complies with rules on privacy.

Legalease is intended for use by non-programming types to specify restrictions on how data is handled. One of the main drivers behind Legalease's development was that software developers and those setting companies’ privacy policies don’t share a common language.

MSR says that more than 20 per cent of the code in Bing changes on a daily basis, with changes made by thousands of programmers. Changes in code might affect how data is used or who views it, potentially violating company, government or regulatory privacy policies.

Keeping tabs on changes in very large systems, like the Bing search engine, using manual audits is difficult. According to MSR automated testing is the best way to verify compliance with privacy rules and laws on the massive scale demanded in environments like Bing.

Legalease uses allow/deny rules, with exceptions. This reflects privacy policy frameworks like the US Health Insurance Portability and Accountability Act (HIPPA).

Grok

Grok, meanwhile, annotates existing code using a system that cross-references information from different sources, based on varying levels of confidence.

According to Microsoft, pattern-matching to column names across a database results in a low-confidence score, while annotations made manually by developers are deemed to be more trustworthy and thus get a high-confidence score.

MSR says it developed Grok for use on Bing but found writing suitable polices hard – and this was what led to Legalese. Both were tested on Bing and are now running on the data analytics pipeline of Microsoft's search engine.

MSR presented Legalese and Grok at the 35th IEEE Symposium on Security and Privacy in San Jose, California, this week. Redmond claims a group of non-coders took less than five minutes to learn how to use Legalease and just 15 minutes to code nine Bing policy clauses on the use of user information.

Saikat Guha, a researcher at Microsoft, in a statement called Legalease “the final piece of the automated privacy compliance jigsaw puzzle."

You can read more on the Microsoft Research site here. ®

Beginner's guide to SSL certificates

More from The Register

next story
Microsoft on the Threshold of a new name for Windows next week
Rebranded OS reportedly set to be flung open by Redmond
Business is back, baby! Hasta la VISTA, Win 8... Oh, yeah, Windows 9
Forget touchscreen millennials, Microsoft goes for mouse crowd
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Apple: SO sorry for the iOS 8.0.1 UPDATE BUNGLE HORROR
Apple kills 'upgrade'. Hey, Microsoft. You sure you want to be like these guys?
ARM gives Internet of Things a piece of its mind – the Cortex-M7
32-bit core packs some DSP for VIP IoT CPU LOL
Lotus Notes inventor Ozzie invents app to talk to people on your phone
Imagine that. Startup floats with voice collab app for Win iPhone
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.