DocumentCode
760657
Title
Inference in MLS database systems
Author
Marks, Donald G.
Author_Institution
Office of INFOSEC/Comput. Sci., U.S. Dept. of Defense, Ft. Meade, MD, USA
Volume
8
Issue
1
fYear
1996
fDate
2/1/1996 12:00:00 AM
Firstpage
46
Lastpage
55
Abstract
Database systems that contain information of varying degrees of sensitivity pose the threat that some of the low data may infer high data. This study derives conditions sufficient to identify such inference threats. First, it is reasoned that a database can only control material implications, as specified in formal logic systems. These material implications are found using knowledge discovery techniques. Material implications allow reasoning about outside knowledge, and provide the first assurance that outside knowledge does not assist in circumventing the inference controls. Database queries specify the properties of sets of data and are compared to help determine inferences. These queries are grouped into equivalence classes based upon their inference characteristics. A unique graph based model is developed for the equivalence classes that (1) makes such comparisons easy, and (2) allows implementation of an algorithm capable of finding those material implication rules where high data is inferred from low data. This is the first method that offers assurance and sufficiency arguments that the mechanism is at least strong enough to protect the high data in the database from inference attacks that require low data
Keywords
database management systems; database theory; formal logic; knowledge acquisition; query processing; security of data; MLS database systems; algorithm; assurance; control material implications; data set properties; database queries; equivalence classes; formal logic systems; graph based model; high data; inference controls; inference threats; information sensitivity; knowledge discovery techniques; low data; multilevel secure database systems; outside knowledge; reasoning; sufficiency; Control systems; Data security; Database systems; Government; Inference algorithms; Information retrieval; Information security; Logic; Multilevel systems; Protection;
fLanguage
English
Journal_Title
Knowledge and Data Engineering, IEEE Transactions on
Publisher
ieee
ISSN
1041-4347
Type
jour
DOI
10.1109/69.485628
Filename
485628
Link To Document