Database Security and Authorization: by Yazmin Escoto Rodriguez Christine Tannuwidjaja
Database Security and Authorization: by Yazmin Escoto Rodriguez Christine Tannuwidjaja
By
Yazmin Escoto Rodriguez
Christine Tannuwidjaja
CLASSIFICATIONS
--class(o)-CLEARANCE
--clear(s)--
Simple Property
protects information
from unauthorized
access
*-property protects
data from
contamination or
unauthorized
modification
Topic
Location
TC
Black, TS
Databases, TS
Los Angeles, TS
Silver, S
Supply Chain, S
New York, S
Gold, U
Inventories, S
Atlanta, S
Indigo, U
Telecommunication, U
Austin, U
TS
Topic
Location
TC
TS
Black, TS
Databases, TS
Los Angeles, TS
Silver, S
Supply Chain, S
New York, S
Gold, U
Inventories, S
Atlanta, S
Indigo, U
Telecommunication, U
Austin, U
Project Name
Topic
Location
TC
Silver, S
Supply Chain, S
New York, S
Gold, U
Inventories, S
Atlanta, S
Indigo, U
Telecommunication, U
Austin, U
Topic
Location
TC
TS
Black, TS
Databases, TS
Los Angeles, TS
Silver, S
Supply Chain, S
New York, S
Gold, U
Inventories, S
Atlanta, S
Indigo, U
Telecommunication, U
Austin, U
Project Name
Topic
Location
TC
Gold, U
-, U
-, U
Indigo, U
Telecommunication, U
Austin, U
Topic
Location
TC
TS
Black, TS
Databases, TS
Los Angeles, TS
Silver, S
Supply Chain, S
New York, S
Gold, U
Inventories, S
Atlanta, S
Indigo, U
Telecommunication, U
Austin, U
Silver, U
Linear Programming, U
Omaha, U
Polyinstantiation : the existence of multiple data objects with the same key
Topic
Location
TC
Gold, U
-, U
-, U
Indigo, U
Telecommunication, U
Austin, U
subject z wants to replace the null values with certain data items
< Markov Chain, New Jersey>
Project Name
Topic
Location
TC
TS
Black, TS
Databases, TS
Los Angeles, TS
Silver, S
Supply Chain, S
New York, S
Gold, U
Inventories, S
Atlanta, S
Indigo, U
Telecommunication, U
Austin, U
Gold, U
Markov Chain, U
New Jersey, U
Classification Constraints
To assign to security classifications concepts of schemas:
- ones that classify items
- ones that classify query results
System Object
What is it?
Notation
Entity type
Specialization type
Relationship type
In security
it is the
target of
protection
O(A1..,An)
- Ai (i=1..N) is an
attribute and is
defined over
domain Di
Has an identity
property (key
attributes)
A (A1,..,An)
[U..S]
(Co)
[Co..TS]
(S)
(TS)
Ranges of Secrecy
Levels
Aggregation leading
to TS (N..constant)
Inference leading to
Co
Evaluation of
predicate P
Security dependency
ER Diagram
SSN
Date
Function
Title
Name
Employee
(0,N)
Is
Assigned
to
(0,M)
Project
Subject
Dep
Client
Salary
SSN
Title
ER Diagram classifying
properties of security objects
SSN
Date
Function
Title
Name
Employee
(0,N)
Is
Assigned
to
(0,M)
Project
Subject
Dep
Client
Salary
SSN
Title
ER Diagram classifying
properties of security objects
SSN
Date
Function
Title
Name
Employee
(0,N)
Is
Assigned
to
(0,M)
Project
Subject
Dep
Client
Salary
SSN
Title
Application to ER:
- CoC (Is Assigned to, {SSN}, Project, Subject, =, Research, S)
- individual assignment data (SSN) is regarded as secret information in
the case the assignment refers to a project with Subject = Research
ER Diagram classifying
properties of security objects
SSN
Date
Function
Title
Name
Employee
(0,N)
Is
Assigned
to
(0,M)
Project
Subject
Dep
Client
Salary
SSN
Title
P
ER Diagram classifying
properties of security objects
SSN
Date
Function
Title
Name
Employee
(0,N)
Is
Assigned
to
(0,M)
Project
Subject
Dep
Client
Salary
SSN
Title
P
ER Diagram
classifying query results
SSN
Date
Function
Title
Name
Employee
(0,N)
Is
Assigned
to
(0,M)
Project
Subject
Dep
Client
[Co]
Salary
SSN
Title
ER Diagram
classifying query results
SSN
Date
Function
Title
Name
Employee
(0,N)
Is
Assigned
to
(0,M)
Project
Subject
Dep
Client
[Co]
Salary
SSN
Title
ER Diagram
classifying query results
SSN
Date
Function
Title
Name
Employee
(0,N)
Is
Assigned
to
(0,M)
Project
Subject
Dep
Client
[Co]
Salary
SSN
Title
QUESTION?