• DocumentCode
    408326
  • Title

    A constraint-based query modification engine for retrofitting COTS DBMS´s

  • Author

    Garuba, Moses ; Langrin, Ronald ; Burge, Legand

  • Author_Institution
    Dept. of Syst. & Comput. Sci., Howard Univ., Washington, DC, USA
  • Volume
    1
  • fYear
    2004
  • fDate
    5-7 April 2004
  • Firstpage
    551
  • Abstract
    Models have been proposed to ensure the secrecy of data using various strategies. A number of these models however do not adequately address the problem of inference. This paper describes the design and implementation of a prototype that uses query modification along with security constraints to accurately return the proper information to the user whilst preventing unauthorized disclosure of data. The strategy works by augmenting a user´s query with security constraints to ensure that the modified query is correct and safe in relation to the user´s clearance level. The prototype is an implementation and extension of the query modification technique proposed by Keefe.
  • Keywords
    authorisation; constraint handling; data privacy; database management systems; query processing; software packages; COTS DBMS; data secrecy; inference problem; query modification engine; security constraints; unauthorized data disclosure; Access control; Banking; Data security; Engines; Information security; Multilevel systems; Personnel; Protection; Prototypes; Relational databases;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Technology: Coding and Computing, 2004. Proceedings. ITCC 2004. International Conference on
  • Print_ISBN
    0-7695-2108-8
  • Type

    conf

  • DOI
    10.1109/ITCC.2004.1286521
  • Filename
    1286521