DocumentCode
1830988
Title
Declassification Policy Management in Dynamic Information Systems
Author
Thomas, Julien A. ; Cuppens-Boulahia, Nora ; Cuppens, Frédéric
Author_Institution
LUSSI Dept., Univ. Eur. de Bretagne, Cesson-Sevigne, France
fYear
2011
fDate
22-26 Aug. 2011
Firstpage
143
Lastpage
152
Abstract
Standard multilevel security (MLS) policies lack flexibility as data classification is considered static. Previous works have addressed this issue and defined declassification requirements, especially in programming languages using a language-based security approach. In this paper, we suggest a dif ferent approach. We show how to define and enforce declassification policies in databases, seen as sets of logical facts. We first define an information flow con trol model where data classification may dynamically change. This model combines both confidentiality and integrity requirements to enforce security. We then specify how to enforce declassification policies. Our approach relies on Event-Condition-Action (ECA) rules and provides means to manage the four basic di mensions of declassification, namely the what?, who?, where? and when? which respectively refer to model ing information to be declassified, entities responsible for declassification, localization of the declassification and contextual conditions that control declassifica tion. We formalize and specify our declassification policies and prove it safe and secure with respect to the information flow control model.
Keywords
database management systems; pattern classification; security of data; data classification; data confidentiality; data integrity; declassification policy management; dynamic information systems; event-condition-action rules; information flow control model; language-based security approach; multilevel security policies; programming languages; Access control; Adaptation models; Data models; Databases; Information systems; Superluminescent diodes;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security (ARES), 2011 Sixth International Conference on
Conference_Location
Vienna
Print_ISBN
978-1-4577-0979-1
Electronic_ISBN
978-0-7695-4485-4
Type
conf
DOI
10.1109/ARES.2011.30
Filename
6045926
Link To Document