Title :
Disclosure prevention in XML
Author :
Mohy, Noha N. ; El-Sharkawi, Mohamed E.
Author_Institution :
Dept. of Inf. Syst., Cairo Univ., Cairo
Abstract :
Information security is considered the most serious requirement which must be carefully considered. Traditional security mechanism protects data at physical level such as encryption and access control, but todaypsilas organizations need to protect data on both levels physical and logical level. Since the organizationpsilas data may be published and shared by many users. Disclosure is a result of weakness of these security mechanisms. In this paper we discuss the problem of protecting XML data at logical level specifically solve the disclosure problem. The objective is to prevent an unauthorized user to infer sensitive information through the data they authorized to access (result of previous queries), integrity constraints, and using inferences. In most existing access control approaches the XML elements specified by access policies are either accessible or inaccessible according to their sensitivity. However, in some cases, the original XML elements are sensitive and inaccessible, but after being processed in some appropriate ways, the results become insensitive and thus accessible [6]. We propose a security mechanism called Disclosure Prevention Algorithm (DPA) that enhances both the security (by preventing disclosure) and availability (by considering suspected users only) of data represented in XML format.
Keywords :
XML; authorisation; XML data; access control; data protection; disclosure prevention; disclosure prevention algorithm; encryption; information security; security mechanism; Access control; Authorization; Cryptography; Data security; Inference algorithms; Information security; Information systems; Leak detection; Protection; XML;
Conference_Titel :
Applications of Digital Information and Web Technologies, 2008. ICADIWT 2008. First International Conference on the
Conference_Location :
Ostrava
Print_ISBN :
978-1-4244-2623-2
Electronic_ISBN :
978-1-4244-2624-9
DOI :
10.1109/ICADIWT.2008.4664412