【24h】

Disclosure Prevention in XML

机译:XML中的披露预防

获取原文

摘要

Information security is considered the most serious requirement which must be carefully considered. Traditional security mechanism protects data at physical level such as encryption and access control, but today's organizations need to protect data on both levels physical and logical level. Since the organization's data may be published and shared by many users. Disclosure is a result of weakness of these security mechanisms. In this paper we discuss the problem of protecting XML data at logical level specifically solve the disclosure problem. The objective is to prevent an unauthorized user to infer sensitive information through the data they authorized to access (result of previous queries), integrity constraints, and using inferences. In most existing access control approaches the XML elements specified by access policies are either accessible or inaccessible according to their sensitivity. However, in some cases, the original XML elements are sensitive and inaccessible, but after being processed in some appropriate ways, the results become insensitive and thus accessible [6]. We propose a security mechanism called Disclosure Prevention Algorithm (DPA) that enhances both the security (by preventing disclosure) and availability (by considering suspected users only) of data represented in XML format.
机译:信息安全被认为是必须仔细考虑的最严重要求。传统的安全机制可以保护数据处于物理级别,如加密和访问控制,但今天的组织需要保护数据上的数据和逻辑级别。由于组织的数据可以由许多用户发布和共享。公开内容是这些安全机制的弱点的结果。在本文中,我们讨论了在逻辑级别保护XML数据的问题,具体解决了披露问题。该目标是防止未经授权的用户通过授权的数据推断敏感信息,他们授权访问(先前查询的结果),完整性约束和使用推断。在大多数现有的访问控制中,接近访问策略指定的XML元素根据其敏感性可访问或无法访问。但是,在某些情况下,原始XML元素是敏感的且无法访问的,但在以某种合适的方式处理之后,结果变得不敏感,因此可访问[6]。我们建议,被称为披露预防算法(DPA)的安全机制增强了双方的安全性(防止泄露)和可用性(仅考虑网友怀疑)的XML格式的数据的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号