• DocumentCode
    1830988
  • Title

    Declassification Policy Management in Dynamic Information Systems

  • Author

    Thomas, Julien A. ; Cuppens-Boulahia, Nora ; Cuppens, Frédéric

  • Author_Institution
    LUSSI Dept., Univ. Eur. de Bretagne, Cesson-Sevigne, France
  • fYear
    2011
  • fDate
    22-26 Aug. 2011
  • Firstpage
    143
  • Lastpage
    152
  • Abstract
    Standard multilevel security (MLS) policies lack flexibility as data classification is considered static. Previous works have addressed this issue and defined declassification requirements, especially in programming languages using a language-based security approach. In this paper, we suggest a dif ferent approach. We show how to define and enforce declassification policies in databases, seen as sets of logical facts. We first define an information flow con trol model where data classification may dynamically change. This model combines both confidentiality and integrity requirements to enforce security. We then specify how to enforce declassification policies. Our approach relies on Event-Condition-Action (ECA) rules and provides means to manage the four basic di mensions of declassification, namely the what?, who?, where? and when? which respectively refer to model ing information to be declassified, entities responsible for declassification, localization of the declassification and contextual conditions that control declassifica tion. We formalize and specify our declassification policies and prove it safe and secure with respect to the information flow control model.
  • Keywords
    database management systems; pattern classification; security of data; data classification; data confidentiality; data integrity; declassification policy management; dynamic information systems; event-condition-action rules; information flow control model; language-based security approach; multilevel security policies; programming languages; Access control; Adaptation models; Data models; Databases; Information systems; Superluminescent diodes;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2011 Sixth International Conference on
  • Conference_Location
    Vienna
  • Print_ISBN
    978-1-4577-0979-1
  • Electronic_ISBN
    978-0-7695-4485-4
  • Type

    conf

  • DOI
    10.1109/ARES.2011.30
  • Filename
    6045926