|
ABSTRACT
It is envisaged that the application of the multilevel security (MLS) scheme will enhance flexibility and effectiveness of authorization policies in shared enterprise databases and will replace cumbersome authorization enforcement practices through complicated view definitions on a per user basis. However, as advances in this area are being made and ideas crystallized, the concomitant weaknesses of the MLS databases are also surfacing. We insist that the critical problem with the current model is that the belief at a higher security level is cluttered with irrelevant or inconsistent data as no mechanism for attenuation is supported. Critics also argue that it is imperative for MLS database users to theorize about the belief of others, perhaps at different security levels, an apparatus that is currently missing and the absence of which is seriously felt.
The impetus for our current research is this need to provide an adequate framework for belief reasoning in MLS databases. We demonstrate that a prudent application of the concept of inheritance in a deductive database setting will help capture the notion of declarative belief and belief reasoning in MLS databases in an elegant way. To this end, we develop a function to compute belief in multiple modes which can be used to reason about the beliefs of other users. We strive to develop a poised and practical logical characterization of MLS databases for the first time based on the inherently difficult concept of non-monotonic inheritance. We present an extension of the acclaimed Datalog language, called the MultiLog, and show that Datalog is a special case of our language. We also suggest an implementation scheme for MultiLog as a front-end for CORAL.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
D. E. Bell and L. J. La Padula. Secure computer systems: Unified exposition and multics interpretation. Technical Report ESD-TR-75-.306, The MITRE Corporation, Bedford, MA, March 1976.
|
| |
2
|
|
| |
3
|
M. Bugliesi. A declarative view of inheritance in logic programming, in K. Apt, editor, Proc. Joint Int. Conference and Symposium on Logic Programming, pages 113-130. The MIT Press, 1992.
|
| |
4
|
|
| |
5
|
|
| |
6
|
|
| |
7
|
|
| |
8
|
D. E. Denning, T. F. Lunt, R. R. Schell, M. Heckman, and W. R. Shockley. A multilevel relational data model. In Proc. of the IEEE Symposium on Security and Privacy, pages 220-234. IEEE Computer Society Press, 1987.
|
| |
9
|
D. Chimenti , R. Gamboa , R. Krishnamurthy , S. Naqvi , S. Tsur , C. Zaniolo, The LDL System Prototype, IEEE Transactions on Knowledge and Data Engineering, v.2 n.1, p.76-90, March 1990
[doi> 10.1109/69.50907]
|
| |
10
|
|
 |
11
|
Sushil Jajodia , Pierangela Samarati , V. S. Subrahmanian , Eliza Bertino, A unified framework for enforcing multiple access control policies, Proceedings of the 1997 ACM SIGMOD international conference on Management of data, p.474-485, May 11-15, 1997, Tucson, Arizona, United States
|
 |
12
|
|
| |
13
|
|
| |
14
|
H. M. Jamil. A logical foundation for mls deductive databases. Technical report, Department of Computer Science, Mississippi State University, USA, November 1998. Submitted for publication.
|
| |
15
|
H. M. Jamil and L. V. S. Lakshmanan. A :leclarative semantics for behavioral inheritance and conflict resolution. In John Lloyd, editor, Proceedings of the 12th International Logic Programming Symposium, pages 130-}{44, Portland, Oregon, December 1995. MIT Press.
|
 |
16
|
|
| |
17
|
V. Kessler and G. Wedel. Autlog- an advanced logic: of authentication. Manuscript.
|
 |
18
|
|
| |
19
|
|
| |
20
|
|
| |
21
|
L. Monteiro and A. Porto. Contextual Logic Programruing. In 6th ALP Intl. Conf. on Logic Pr~,ramming, 1989.
|
| |
22
|
G. Pernul, W. Winiwarter, and A. M. Tj()a. The deductive filter approach to mls database proto~:yping, in Proc. of the 9th Annual Computer Security A~plications Conference, Orlando, FL, December 1993.
|
| |
23
|
|
| |
24
|
|
| |
25
|
A Spalka. Fundamental forms of confiden;iality in deductive databases. Manuscript.
|
| |
26
|
W. Winiwarter. Why is deduction required for database systems ? - some case studies. In Proc. of the ~nd Data Engineering Forum, Tokyo, Japan, November 1995.
|
 |
27
|
|
|