• DocumentCode
    2867655
  • Title

    Dynamic Enforcement of Knowledge-Based Security Policies

  • Author

    Mardziel, Piotr ; Magill, Stephen ; Hicks, Michael ; Srivatsa, Mudhakar

  • Author_Institution
    Univ. of Maryland, College Park, MD, USA
  • fYear
    2011
  • fDate
    27-29 June 2011
  • Firstpage
    114
  • Lastpage
    128
  • Abstract
    This paper explores the idea of knowledge-based security policies, which are used to decide whether to answer queries over secret data based on an estimation of the querier´s (possibly increased) knowledge given the results. Limiting knowledge is the goal of existing information release policies that employ mechanisms such as noising, anonymization, and redaction. Knowledge-based policies are more general: they increase flexibility by not fixing the means to restrict information flow. We enforce a knowledge-based policy by explicitly tracking a model of a querier´s belief about secret data, represented as a probability distribution, and denying any query that could increase knowledge above a given threshold. We implement query analysis and belief tracking via abstract interpretation using a novel probabilistic polyhedral domain, whose design permits trading off precision with performance while ensuring estimates of a querier´s knowledge are sound. Experiments with our implementation show that several useful queries can be handled efficiently, and performance scales far better than would more standard implementations of probabilistic computation based on sampling.
  • Keywords
    belief networks; knowledge based systems; probability; security of data; belief tracking; dynamic enforcement; information flow; knowledge-based security policy; probabilistic computation; probabilistic polyhedral domain; query analysis; Data models; Facebook; Knowledge based systems; Probabilistic logic; Security; Semantics; Waste materials; abstract interpretation; knowledge-based security; privacy; probabilistic polyhedron;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Foundations Symposium (CSF), 2011 IEEE 24th
  • Conference_Location
    Cernay-la-Ville
  • ISSN
    1940-1434
  • Print_ISBN
    978-1-61284-644-6
  • Type

    conf

  • DOI
    10.1109/CSF.2011.15
  • Filename
    5992158