Database Inference Problem

Csilla Farkas

Alexander Brodsky

Sushil Jajodia

Tyrone Toland

Caroline Eastman

Most of the existing works on data secrecy are focused on developing mandatory and discretionary accesses control models. While these models do protect sensitive information from direct data accesses, indirect secrecy violations via inference channels may occur. The detection and removal of existing inference channels are necessary to provide secure database systems.

We study the database inference problem in multilevel secure relational, semi-structured, and numeric databases.  We also consider the effect of updates on the inference problem. 

Future extensions of the current results include the development of models addressing collaborative attacker.  Currently each user is monitored and inferences are generated only on his/her history files.  Also, I’m planning to evaluate the inference problem from the perspective of privacy and fairness.  Disclosing seemingly unimportant or non-sensitive information may give advantage to an adversary.  In particular, it may play an important role in interactive negotiation and trust management. 


