A framework for access control with inference constraints

Authors: Katos, V., Vrakas, D. and Katsaros, P.

Journal: Proceedings - International Computer Software and Applications Conference

Pages: 289-297

ISSN: 0730-3157

DOI: 10.1109/COMPSAC.2011.45

Abstract:

In this paper we present an approach for investigating the feasibility of reducing inference control to access control, as the latter is a more desirable means of preventing unauthorized access to sensitive data. Access control is preferable over inference control in terms of efficiency, but it fails to offer confidentiality in the presence of inference channels. We argue that during the design phase of a data schema and the definition of user roles, inference channels should be considered. An approach is introduced that can be integrated into a risk assessment exercise to assist in determining the roles and/or attributes that lower the risks associated with information disclosure from inference. The residual risk from the remaining inference channels could be treated by well known inference control mechanisms. © 2011 IEEE.

Source: Scopus

Preferred by: Vasilis Katos

A Framework for Access Control with Inference Constraints

Authors: Katos, V., Vrakas, D. and Katsaros, P.

Journal: 2011 35TH IEEE ANNUAL INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC)

Pages: 289-297

ISSN: 0730-3157

DOI: 10.1109/COMPSAC.2011.45

Source: Web of Science (Lite)