Sciweavers

ESORICS
1994
Springer

Aggregation in Relational Databases: Controlled Disclosure of Sensitive Information

13 years 8 months ago
Aggregation in Relational Databases: Controlled Disclosure of Sensitive Information
It has been observed that often the release of a limited part of an information resource poses no security risks, but the relase of a sufficiently large part of that resource might pose such risks. This problem of controlled disclosure of sensitive information is an example of what is known as the aggregation problem. In this paper we argue that it should be possible to articulate specific secrets within a database that should be protected against overdisclosure, and we provide a general framework in which such controlled disclosure can be achieved. Our methods foil any attempt to attack these predefined secrets by disguising queries as queries whose definitions do not resemble secrets, but whose answers nevertheless "nibble" at secrets. Our methods also foil attempts to attack secrets by breaking queries into sequences of smaller requests that extract information less conspicuously. The accounting methods we employ to thwart such attempts are shown to be both accurate and ec...
Amihai Motro, Donald G. Marks, Sushil Jajodia
Added 27 Aug 2010
Updated 27 Aug 2010
Type Conference
Year 1994
Where ESORICS
Authors Amihai Motro, Donald G. Marks, Sushil Jajodia
Comments (0)