Aggregation in Relational Databases: Controlled Disclosure of Sensitive Information
نویسندگان
چکیده
It has been observed that often the release of a limited part of an information resource poses no security risks, but the relase of a sufficiently large part of that resource might pose such risks. This problem of controlled disclosure of sensitive information is an example of what is known as the aggregation problem. In this paper we argue that it should be possible to articulate specific secrets within a database that should be protected against overdisclosure, and we provide a general framework in which such controlled disclosure can be achieved. Our methods foil any attempt to attack these predefined secrets by disguising queries as queries whose definitions do not resemble secrets, but whose answers nevertheless “nibble” at secrets. Our methods also foil attempts to attack secrets by breaking queries into sequences of smaller requests that extract information less conspicuously. The accounting methods we employ to thwart such attempts are shown to be both accurate and economical.
منابع مشابه
Enhancing the Controlled Disclosure of Sensitive Information
The so-called “aggregation problem” is addressed, where the issue is how to release only a limited part of an information resource, and foil any attacks by users trying to aggregate information beyond the preset limits. The framework is that of relational databases, where sensitive information can be defined flexibly using view definitions. For each such view, the tuples that have already been ...
متن کاملBuilding Disclosure Risk Aware Query Optimizers for Relational Databases
Many DBMS products in the market provide built in encryption support to deal with the security concerns of the organizations. This solution is quite effective in preventing data leakage from compromised/stolen storage devices. However, recent studies show that a significant part of the leaked records have been done so by using specialized malwares that can access the main memory of systems. The...
متن کاملLimiting Disclosure in Hippocratic Databases
Preserving data privacy is of utmost concern in many sectors, including e-commerce, healthcare, government, and retail, where individuals entrust others with their personal information every day. Often, the organizations collecting the data will specify how the data is to be used in a privacy policy, which can be expressed either electronically or in natural language. We describe a data model f...
متن کاملInvestigation and Ranking the Disclosure of Dimensions, Components and Indicators of Intellectual Capital by Analytical Hierarchy process (AHP) method in companies accepted in Tehran Stock Exchange
The present research seeks to determine the model for ranking the importance of disclosing the dimensions, components and indicators of intellectual capital in Iran through Analytical Hierarchy process (AHP) method. Initially, experts' views include university professors, corporate finance managers, Members of the Iranian Association of Certified Public Accountants and stock brokers are e...
متن کاملA Method for Protecting Access Pattern in Outsourced Data
Protecting the information access pattern, which means preventing the disclosure of data and structural details of databases, is very important in working with data, especially in the cases of outsourced databases and databases with Internet access. The protection of the information access pattern indicates that mere data confidentiality is not sufficient and the privacy of queries and accesses...
متن کامل