Granularity of Data Protection for MLS Applications and DBMSs
نویسندگان
چکیده
A secure Database Management System (DBMS) will be widely adopted only if it provides a convenient base for application development. Given this assumption, we examine two questions: "Should an application’s view of the database consist of objects whose attributes are at more than one security level" and "Should a DBMS directly support such multilevel objects?" We investigate the impact on MLS application development of alternative degrees of DBMS support. Performance estimates and a comparison methodology are also presented. We conclude that applications should be built using object classes that capture natural real world entities and whose instances may include elements at different security levels. We then show that direct DBMS support for such classes can be quite helpful. As a byproduct, our analysis describes how untrusted code can decompose operations on multilevel objects into operations on single-level objects.
منابع مشابه
Concurrency Control for Multilevel Secure Databases
A multilevel secure database is intended to protect classified information from unauthorized users based on the classification of the data and the clearances of the users. The concurrency control requirements for transaction processing in multilevel secure database management systems (MLS/DBMSs) are different from those in conventional transaction processing systems. In MLS/DBMSs, coordination ...
متن کاملDesign and Implementation of a Database Inference Controller
The Inference Problem compromises database systems which are usually considered to be secure. Here, users pose sets of queries and infer unauthorized information from the responses that they obtain. An Inference Controller is a device that prevents and/or detects security violations via inference. We are particularly interested in the inference problem which occurs in a multilevel operating env...
متن کاملROAD DATA INFORMATION SYSTEM; BUDAPEST CASE STUDY
Budapest Közút is developing ROad Data Information System based on mobile laser scanning since 2013. All public roads (cca. 5000 km) are surveyed by MLS (Riegl VMX450) in survey grade accuracy and all visible road assets has been digitized and loaded to a complex 3D GIS environment. Since the first full coverage had been done in 2014 the whole city has also been updated - being one of the few l...
متن کاملATLaS: A Native Extension of SQL for Data Mining
A lack of power and extensibility in their query languages has seriously limited the generality of DBMSs and hampered their ability to support data mining applications. Thus, there is a pressing need for more general mechanisms for extending DBMSs to support efficiently database-centric data mining appliacations. To satisfy this need, we propose a new extensibility mechanism for SQL-compliant D...
متن کاملScalable and Elastic Transactional Data Stores for Cloud Computing Platforms
Scalable and Elastic Transactional Data Stores for Cloud Computing Platforms by Sudipto Das Cloud computing has emerged as a multi-billion dollar industry and as a successful paradigm for web application deployment. Economies-of-scale, elasticity, and pay-peruse pricing are the biggest promises of cloud. Database management systems (DBMSs) serving these web applications form a critical componen...
متن کامل