The Curse of Correlations for Robust Fingerprinting of Relational Databases

The Curse of Correlations for Robust Fingerprinting of Relational Databases
复制标题

DOI:
10.1145/3471621.3471853
复制
发表时间:
2021-03
期刊:
Proceedings of the 24th International Symposium on Research in Attacks, Intrusions and Defenses
影响因子:
--
通讯作者:
Tianxi Ji;Emre Yilmaz;Erman Ayday;Pan Li
Tianxi Ji;Emre Yilmaz;Erman Ayday;Pan Li
中科院分区:
其他
文献类型:
--
作者:
Tianxi Ji;Emre Yilmaz;Erman Ayday;Pan Li

文献摘要

被引文献

相似文献

数据库指纹识别已被广泛采用,以防止未经授权的数据共享和识别数据泄漏的来源。虽然现有方案对随机比特翻转和子集攻击等常见攻击具有很好的鲁棒性,但如果攻击者利用数据库条目之间的内在相关性,它们的稳健性会显著降低。在本文中,我们首先通过识别不同的关联攻击来证明现有数据库指纹识别方案的脆弱性:列关联攻击、行关联攻击以及它们的集成。为了针对已识别的相关攻击提供健壮的指纹识别,我们开发了缓解技术,该技术可以作为任何现成的数据库指纹识别方案的后处理步骤。考虑到不同的效用度量,所提出的缓解技术还保留了指纹数据库的效用。我们使用真实世界的关系数据库对识别的关联攻击的影响和缓解技术的性能进行了实证研究。我们的结果表明:(I)针对现有指纹方案的识别相关攻击的成功率很高(例如,集成相关攻击仅通过修改指纹数据库中14.2%的条目就可以扭曲64.8%的指纹比特),以及(Ii)所提出的缓解技术的高稳健性(例如,在缓解技术的情况下,集成相关攻击只能扭曲3%的指纹比特)。
Database fingerprinting have been widely adopted to prevent unauthorized sharing of data and identify the source of data leakages. Although existing schemes are robust against common attacks, like random bit flipping and subset attack, their robustness degrades significantly if attackers utilize the inherent correlations among database entries. In this paper, we first demonstrate the vulnerability of existing database fingerprinting schemes by identifying different correlation attacks: column-wise correlation attack, row-wise correlation attack, and the integration of them. To provide robust fingerprinting against the identified correlation attacks, we then develop mitigation techniques, which can work as post-processing steps for any off-the-shelf database fingerprinting schemes. The proposed mitigation techniques also preserve the utility of the fingerprinted database considering different utility metrics. We empirically investigate the impact of the identified correlation attacks and the performance of mitigation techniques using real-world relational databases. Our results show (i) high success rates of the identified correlation attacks against existing fingerprinting schemes (e.g., the integrated correlation attack can distort 64.8% fingerprint bits by just modifying 14.2% entries in a fingerprinted database), and (ii) high robustness of the proposed mitigation techniques (e.g., with the mitigation techniques, the integrated correlation attack can only distort 3% fingerprint bits).