| Redundancy and information leakage in fine-grained access control |
| Full text |
Pdf
(340 KB)
|
| Source
|
International Conference on Management of Data
archive
Proceedings of the 2006 ACM SIGMOD international conference on Management of data
table of contents
Chicago, IL, USA
SESSION: Authentication
table of contents
Pages: 133 - 144
Year of Publication: 2006
ISBN:1-59593-434-0
|
|
Authors
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 7, Downloads (12 Months): 135, Citation Count: 0
|
|
|
ABSTRACT
The current SQL standard for access control is coarse grained, in that it grants access to all rows of a table or none. Fine-grained access control, which allows control of access at the granularity of individual rows, and to specific columns within those rows, is required in practically all database applications. There are several models for fine grained access control, but the majority of them follow a view replacement strategy. There are two significant problems with most implementations of the view replacement model, namely (a) the unnecessary overhead of the access control predicates when they are redundant and (b) the potential of information leakage through channels such as user-defined functions, and operations that cause exceptions and error messages. We first propose techniques for redundancy removal. We then define when a query plan is safe with respect to UDFs and other unsafe functions, and propose techniques to generate safe query plans. We have prototyped redundancy removal and safe UDF pushdown on the Microsoft SQL Server query optimizer, and present a preliminary performance study.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Rakesh Agrawal , Paul Bird , Tyrone Grandison , Jerry Kiernan , Scott Logan , Walid Rjaibi, Extending Relational Database Systems to Automatically Enforce Privacy Policies, Proceedings of the 21st International Conference on Data Engineering (ICDE'05), p.1013-1022, April 05-08, 2005
[doi> 10.1109/ICDE.2005.64]
|
| |
2
|
|
 |
3
|
|
| |
4
|
K. LeFevre, R. Agrawal, V. Ercegovac, R. Ramakrishnan, Y. Xu and D. DeWitt, Limiting disclosure in Hippocratic databases, In VLDB, 2004
|
| |
5
|
|
| |
6
|
G. Graefe, The Cascades Optimization Framework, Data Engg. Bulletin, 1995
|
| |
7
|
D. Litchfield, Web Application Disassembly with ODBC Error Messages, 2001, http://www.blackhat.com/presen-tations/win-usa-01/Litchfield/BHWin01Litchfield.doc
|
| |
8
|
|
| |
9
|
The Virtual Private Database in Oracle9ir2: An Oracle Technical White Paper http://otn.oracle.com/deploy/security/oracle9ir2/pdf/vpd9ir2twp.pdf.
|
| |
10
|
New Security Features in Sybase Adaptive Server Enterprise. Sybase Technical White Paper, 2003.
|
 |
11
|
|
| |
12
|
A. Rosenthal and E. Sciore. Abstracting and Refining Authorization in SQL. In Secure Data Management (SDM) workshop, In VLDB, 2004.
|
 |
13
|
|
|