IFDB: decentralized information flow control for databases

IFDB: decentralized information flow control for databases
复制标题

IFDB:数据库的分散信息流控制

DOI:
10.1145/2465351.2465357
复制
发表时间:
2013
影响因子:
2.7
通讯作者:
B. Liskov
B. Liskov
中科院分区:
医学4区
文献类型:
--
作者:
David A. Schultz;B. Liskov

文献摘要

被引文献

相似文献

由于应用程序中的错误,每年都有许多敏感数据库被破坏。这些应用程序通常为许多用户处理数据,因此,它们可以访问大量机密信息。 本文介绍了IFDB,一个数据库管理系统,通过使用分散信息流控制(DIFC)的安全数据库。我们提出了标签查询模型,它引入了新的抽象管理在关系数据库中的信息流。IFDB还解决了将DIFC引入数据库所固有的几个挑战,包括如何在不引入隐蔽通道的情况下处理事务和完整性约束。 我们通过修改PostgreSQL实现了IFDB,并扩展了PHP和Python两个应用环境,提供了一个DIFC平台。IFDB发现了几个安全漏洞,并在我们移植到平台的两个Web应用程序中防止了信息泄露。我们的评估表明,IFDB的吞吐量是一样好的PostgreSQL的一个真实的Web应用程序,和大约1%的基于TPC-C的数据库基准低。
Numerous sensitive databases are breached every year due to bugs in applications. These applications typically handle data for many users, and consequently, they have access to large amounts of confidential information. This paper describes IFDB, a DBMS that secures databases by using decentralized information flow control (DIFC). We present the Query by Label model, which introduces new abstractions for managing information flows in a relational database. IFDB also addresses several challenges inherent in bringing DIFC to databases, including how to handle transactions and integrity constraints without introducing covert channels. We implemented IFDB by modifying PostgreSQL, and extended two application environments, PHP and Python, to provide a DIFC platform. IFDB caught several security bugs and prevented information leaks in two web applications we ported to the platform. Our evaluation shows that IFDB's throughput is as good as PostgreSQL for a real web application, and about 1% lower for a database benchmark based on TPC-C.