• DocumentCode
    3256911
  • Title

    Disclosure prevention in XML

  • Author

    Mohy, Noha N. ; El-Sharkawi, Mohamed E.

  • Author_Institution
    Dept. of Inf. Syst., Cairo Univ., Cairo
  • fYear
    2008
  • fDate
    4-6 Aug. 2008
  • Firstpage
    573
  • Lastpage
    578
  • Abstract
    Information security is considered the most serious requirement which must be carefully considered. Traditional security mechanism protects data at physical level such as encryption and access control, but todaypsilas organizations need to protect data on both levels physical and logical level. Since the organizationpsilas data may be published and shared by many users. Disclosure is a result of weakness of these security mechanisms. In this paper we discuss the problem of protecting XML data at logical level specifically solve the disclosure problem. The objective is to prevent an unauthorized user to infer sensitive information through the data they authorized to access (result of previous queries), integrity constraints, and using inferences. In most existing access control approaches the XML elements specified by access policies are either accessible or inaccessible according to their sensitivity. However, in some cases, the original XML elements are sensitive and inaccessible, but after being processed in some appropriate ways, the results become insensitive and thus accessible [6]. We propose a security mechanism called Disclosure Prevention Algorithm (DPA) that enhances both the security (by preventing disclosure) and availability (by considering suspected users only) of data represented in XML format.
  • Keywords
    XML; authorisation; XML data; access control; data protection; disclosure prevention; disclosure prevention algorithm; encryption; information security; security mechanism; Access control; Authorization; Cryptography; Data security; Inference algorithms; Information security; Information systems; Leak detection; Protection; XML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Applications of Digital Information and Web Technologies, 2008. ICADIWT 2008. First International Conference on the
  • Conference_Location
    Ostrava
  • Print_ISBN
    978-1-4244-2623-2
  • Electronic_ISBN
    978-1-4244-2624-9
  • Type

    conf

  • DOI
    10.1109/ICADIWT.2008.4664412
  • Filename
    4664412