• DocumentCode
    1426179
  • Title

    Secure databases: constraints, inference channels, and monitoring disclosures

  • Author

    Brodsky, Alexander ; Farkas, Csilla ; Jajodia, Sushil

  • Author_Institution
    Dept. of Comput. Sci. & Eng., South Carolina Univ., Columbia, SC, USA
  • Volume
    12
  • Issue
    6
  • fYear
    2000
  • Firstpage
    900
  • Lastpage
    919
  • Abstract
    Investigates the problem of inference channels that occur when database constraints are combined with non-sensitive data to obtain sensitive information. We present an integrated security mechanism, called the Disclosure Monitor, which guarantees data confidentiality by extending the standard mandatory access control mechanism with a Disclosure Inference Engine. This generates all the information that can be disclosed to a user based on the user´s past and present queries and the database and metadata constraints. The Disclosure Inference Engine operates in two modes: a data-dependent mode, when disclosure is established based on the actual data items, and a data-independent mode, when only queries are utilized to generate the disclosed information. The disclosure inference algorithms for both modes are characterized by the properties of soundness (i.e. everything that is generated by the algorithm is disclosed) and completeness (i.e. everything that can be disclosed is produced by the algorithm). The technical core of this paper concentrates on the development of sound and complete algorithms for both data-dependent and data-independent disclosures
  • Keywords
    data integrity; data privacy; decidability; inference mechanisms; security of data; system monitoring; Disclosure Inference Engine; Disclosure Monitor; completeness; data confidentiality; data-dependent mode; data-independent mode; database constraints; decidability; disclosed information generation; disclosure inference algorithms; inference channels; integrated security mechanism; mandatory access control mechanism; metadata constraints; multi-level security; nonsensitive data; secure databases; sensitive information; soundness; user queries; Access control; Character generation; Data security; Engines; Inference algorithms; Information security; Monitoring; Protection; Relational databases; Remuneration;
  • fLanguage
    English
  • Journal_Title
    Knowledge and Data Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1041-4347
  • Type

    jour

  • DOI
    10.1109/69.895801
  • Filename
    895801