Qapla: Policy compliance for database-backed systems

Qapla: Policy compliance for database-backed systems
复制标题

Qapla:数据库支持系统的策略合规性

DOI:
--
复制
发表时间:
2017
期刊:
USENIX Security Symposium
影响因子:
--
通讯作者:
P. Druschel
P. Druschel
中科院分区:
--
文献类型:
--
作者:
Aastha Mehta;Eslam Elnikety;Katura Harvey;D. Garg;P. Druschel

文献摘要

被引文献

相似文献

许多数据库支持的系统存储了代表具有不同特权的用户访问的机密数据。角色)和查询中使用的运算符(例如,聚合器,组和加入)。查询,易于应用程序错误,QAPLA提供了一种替代的策略执行方法,该方法既不取决于应用程序正确性,也不依赖于QAPLA的专用数据库。 ,在SQL中指定,并存储在数据库中的数据库中。系统和用于管理学术工作应用的系统。
Many database-backed systems store confidential data that is accessed on behalf of users with different privileges. Policies governing access are often fine-grained, being specific to users, time, accessed columns and rows, values in the database (e.g., user roles), and operators used in queries (e.g., aggregators, group by, and join). Today, applications are often relied upon to issue policy compliant queries or filter the results of non-compliant queries, which is vulnerable to application errors. Qapla provides an alternate approach to policy enforcement that neither depends on application correctness, nor on specialized database support. In Qapla, policies are specific to rows and columns and may additionally refer to the querier’s identity and time, are specified in SQL, and stored in the database itself. We prototype Qapla in a database adapter, and evaluate it by enforcing applicable policies in the HotCRP conference management system and a system for managing academic job applications.