Title
Dynamic Enforcement of Knowledge-Based Security Policies
Abstract
This paper explores the idea of knowledge-based security policies, which are used to decide whether to answer queries over secret data based on an estimation of the querier's (possibly increased) knowledge given the results. Limiting knowledge is the goal of existing information release policies that employ mechanisms such as noising, anonymization, and redaction. Knowledge-based policies are more general: they increase flexibility by not fixing the means to restrict information flow. We enforce a knowledge-based policy by explicitly tracking a model of a querier's belief about secret data, represented as a probability distribution, and denying any query that could increase knowledge above a given threshold. We implement query analysis and belief tracking via abstract interpretation using a novel probabilistic polyhedral domain, whose design permits trading off precision with performance while ensuring estimates of a querier's knowledge are sound. Experiments with our implementation show that several useful queries can be handled efficiently, and performance scales far better than would more standard implementations of probabilistic computation based on sampling.
Year
DOI
Venue
2011
10.1109/CSF.2011.15
Computer Security Foundations Symposium
Keywords
Field
DocType
belief networks,knowledge based systems,probability,security of data,belief tracking,dynamic enforcement,information flow,knowledge-based security policy,probabilistic computation,probabilistic polyhedral domain,query analysis,abstract interpretation,knowledge-based security,privacy,probabilistic polyhedron
Information flow (information theory),Data modeling,Abstract interpretation,Computer science,Knowledge-based systems,Theoretical computer science,Implementation,Security policy,Probabilistic logic,restrict
Conference
ISSN
ISBN
Citations 
1940-1434
978-1-61284-644-6
24
PageRank 
References 
Authors
0.92
19
4
Name
Order
Citations
PageRank
Piotr Mardziel11069.37
Stephen Magill2833.54
Michael W. Hicks3106161.49
Mudhakar Srivatsa4108477.97