首页> 外文OA文献 >Dynamic Enforcement of Knowledge-based Security Policies
【2h】

Dynamic Enforcement of Knowledge-based Security Policies

机译:动态执行基于知识的安全策略

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

This paper explores the idea of knowledge-based security policies, whichare used to decide whether to answer a query over secret data based onan estimation of the querier's (possibly increased) knowledge given theresult. Limiting knowledge is the goal of existing information releasepolicies that employ mechanisms such as noising, anonymization, andredaction. Knowledge-based policies are more general: they increaseflexibility by not fixing the means to restrict information flow. Weenforce a knowledge-based policy by explicitly tracking a model of aquerier's belief about secret data, represented as a probabilitydistribution. We then deny any query that could increase knowledge abovea given threshold. We implement query analysis and belief tracking viaabstract interpretation using a novel domain we call probabilisticpolyhedra, whose design permits trading off precision with performancewhile ensuring estimates of a querier's knowledge are sound. Experimentswith our implementation show that several useful queries can be handledefficiently, and performance scales far better than would more standardimplementations of probabilistic computation based on sampling.
机译:本文探讨了基于知识的安全策略的思想,该策略用于基于对查询者(可能增加的)知识的估计来决定是否回答对秘密数据的查询。限制知识是采用诸如噪声,匿名化和编辑之类的机制的现有信息发布策略的目标。基于知识的策略更为笼统:它们通过不固定限制信息流的方式来提高灵活性。通过显式跟踪查询者对机密数据的信任模型(表示为概率分布),我们可以实施基于知识的策略。然后,我们拒绝任何可能使知识增加到给定阈值以上的查询。我们使用一个称为probabilisticpolyhedra的新颖域,通过抽象解释来实现查询分析和信念跟踪,该域的设计允许在权衡精度与性能的同时确保对查询者知识的估计是正确的。通过我们的实现进行的实验表明,可以有效地处理几个有用的查询,并且性能扩展比基于采样的概率计算的更多标准实现要好得多。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号