Title :
Performance study of a MLS/DBMS implemented as a kernelized architecture
Author :
Garuba, Moses ; Appiah, Edward ; Burge, Legand, III
Author_Institution :
Dept. of Syst. & Comput. Sci., Howard Univ., Washington, DC, USA
Abstract :
Although users of multi-level secure database management system (MLS/DBMS) continue to rely on existing systems to satisfy their multi-level security needs, these systems no longer enjoy direct commercial-off-the-shelf (COTS) support. This calls for a renewed approach to developing MLS/DBMS systems. We advocate fragmentation as a good basis for implementing multi-level security, and to this end we implemented a prototype MLS/DBMS that utilizes the inherent advantages of the distribution scheme in distributed databases for controlling access to single-level fragments. Experiments were instrumented to determine the relative performance of the tuple, attribute, and element level fragmentation schemes. The experiments measured the impact of varying the number of tuples, attributes, security levels, and nodes, for a selection and join query. Overall, our study finds that the attribute level fragmentation scheme demonstrates superior performance to the tuple and element level schemes. The response times (and hence the performance) of the element level fragmentation scheme exhibited the worst performance degradation compared to the tuple and attribute level schemes.
Keywords :
distributed databases; security of data; MLS/DBMS; access control; attribute level fragmentation; commercial-off-the-shelf support; distributed databases; kernelized architecture; multilevel secure database management system; multilevel security; Access control; Computer architecture; Computer science; Data security; Database systems; Distributed databases; Information retrieval; Instruments; Multilevel systems; Prototypes;
Conference_Titel :
Information Technology: Coding and Computing, 2004. Proceedings. ITCC 2004. International Conference on
Print_ISBN :
0-7695-2108-8
DOI :
10.1109/ITCC.2004.1286524