首页> 外文学位 >A tradeoff analysis between data accessibility and inference control for row, column, and cell level security in relational databases.
【24h】

A tradeoff analysis between data accessibility and inference control for row, column, and cell level security in relational databases.

机译:在关系数据库中的行,列和单元级安全性的数据可访问性与推理控制之间进行权衡分析。

获取原文
获取原文并翻译 | 示例

摘要

There is a need to protect data in relational databases from unauthorized access at finer levels of granularity and thereby make as much data available to the user as possible. Current state-of-the-art security techniques offer elegant ways to protect data at the column, row and cell levels. But for some patterns of secret cells, these techniques mask innocent data along with the secret data thus reducing data accessibility of the database. This study compares the current security techniques in terms of data accessibility for typical patterns of secret cells.; Another aspect of the current techniques is the possibility of inference based on data that appears to be absent in the database. This is a problem with cell-level security, because the absence of a value returned from a query indicates that a certain cell must contain secret data. This research studies the inference problem associated with these security techniques. A new technique is proposed that suppresses some innocent data in addition to the secret cells. This not only achieves better results in terms of data accessibility for typical patterns of secret cells than row or column level security but also controls data-suppression based inference to a reasonable degree.; The research is a step towards building an add-on tool that measures data accessibility and security from making inferences. A database administrator will input the total number of secret cells in the database and the tool will measure data accessibility and security with all security techniques. The tool will offer a choice to the DBA to pick a security technique based on the requirements for data accessibility versus security.
机译:需要保护关系数据库中的数据免受更细粒度的未经授权的访问,从而使尽可能多的数据可供用户使用。当前最先进的安全技术提供了优雅的方法来保护列,行和单元格级别的数据。但是对于某些秘密单元格模式,这些技术会掩盖无害数据以及秘密数据,从而降低了数据库的数据可访问性。这项研究从典型的秘密细胞模式的数据可访问性方面比较了当前的安全技术。当前技术的另一方面是基于数据库中似乎不存在的数据进行推理的可能性。这是单元级安全性的问题,因为缺少从查询返回的值表示某个单元必须包含机密数据。这项研究研究了与这些安全技术相关的推理问题。提出了一种新技术,该技术可抑制除秘密单元格外的一些无辜数据。与行或列级安全性相比,这不仅在秘密单元的典型模式的数据可访问性方面获得了更好的结果,而且还可以合理地控制基于数据抑制的推理。这项研究是朝着构建一个附加工具迈出的一步,该附加工具可通过推理来测量数据的可访问性和安全性。数据库管理员将输入数据库中秘密单元格的总数,该工具将使用所有安全技术来衡量数据的可访问性和安全性。该工具将为DBA提供一个选择,以根据数据可访问性与安全性的要求选择一种安全技术。

著录项

  • 作者

    Rauf, Azhar.;

  • 作者单位

    Colorado Technical University.;

  • 授予单位 Colorado Technical University.;
  • 学科 Computer Science.
  • 学位 D.CS.
  • 年度 2007
  • 页码 147 p.
  • 总页数 147
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

  • 入库时间 2022-08-17 11:39:58

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号