课题基金 / 基金详情

Controlled Release of Information Based on Contents

Controlled Release of Information Based on Contents
按内容控制信息发布
批准号:
0242237
负责人:
Sushil Jajodia
金额:
$0.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-06-15 至 2008-05-31

项目摘要

项目成果

Sushil Jajodia的其他基金

相似基金

相关文献

中文摘要
翻译
传统上,访问控制用于将用户限制为可用数据的有限视图。尽管早期的访问控制模型是为结构化数据设计的,但它们正在扩展以处理XML数据。然而,访问控制并不总是足以保护复杂的信息环境。例如,威胁可能来自对信息或用户的错误分类、从合法获得的数据中推导出推论、用户之间未经授权的信息交换以及从不同内部来源获得的数据的组合。这项提议将对目前的访问控制机制使用一种补充方法,其基础是检查数据,而不是在从数据源提取数据之前,而是在它们被发布到代表关键安全边界的大门时。检查过程不像当前的防火墙系统那样简单地基于源/目标地址,或者像当前的过滤软件那样基于简单的“脏字”匹配,而是基于基于发布限制的更深层次的内容分析。为了实现这一目标,需要一个全面的框架,其中考虑到外发数据可能具有的不同格式、放行管制规则的复杂性和多样性,以及为安保人员定义和管理这些规则提供的必要支持。这种方法的一个主要特点是将关键数据的规范(称为受控项目)与其与任何传出信息的匹配方式分开。定义这样的框架所涉及的技术问题包括:(I)指定适当的形式来表示受控项目和匹配规则,(Ii)从访问控制规则自动导出受控项目并将其与安全人员提供的受控项目集成,(Iii)计算受控项目和匹配规则的完整和最小表示,以及(Iv)能够处理不同匹配规则和数据格式的高效匹配算法的设计。
英文摘要
Traditionally, access controls have been used to restrict users to limited views of available data. Although early access control models were devised for structured data, they are being extended to deal with XML data. Access controls, however, are not always sufficient to secure complex information environments. Threats may come, for example, from incorrect categorization of information or users, derivation of inferences from legally obtained data, unauthorized exchanges of information between users, and combining data obtained from different internal sources.This proposal will use a complementary approach to current access control mechanisms based on checking data not before they are extracted from data sources, but when they are released across a gate representing a critical security boundary. The checking process is not based simply on source/destination addresses as in current firewall systems, or on simple ``dirty word'' matching as in current filtering software, but on a deeper content analysis based on release constraints. In order to achieve this objective, a comprehensive framework is required that takes into account the different formats outgoing data can have, the complexity and diversity of release control rules, and the necessary support for the security officers in the definition and management of these rules. A major characteristic of this approach to separate the specification of critical data, called the controlled items, from the way it is matched against any outgoing information. Technical problems involved in the definition of such a framework include (i) the specification of appropriate formalisms to represent controlled items and matching rules, (ii) the automatic derivation of controlled items from access control rules and their integration with controlled items provided by security officers, (iii) the computation of complete and minimal representation of controlled items and matching rules, and (iv) the design of efficient matching algorithms that are capable of dealing with different matching rules and data formats.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Phase II IUCRC George Mason University: Center for Cybersecurity Analytics and Automation CCAA
  • 批准号:
    1822094
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $49.96万
  • 财政年份:
    2018
  • 负责人:
    Sushil Jajodia
  • 依托单位:
I/UCRC: Collaborative Research: I/UCRC Program Center for Configuration Analytics and Automation
  • 批准号:
    1266147
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $30.0万
  • 财政年份:
    2013
  • 负责人:
    Sushil Jajodia
  • 依托单位:
Planning Grant: I/UCRC for Configuration Analytics and Automation
  • 批准号:
    1161009
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.63万
  • 财政年份:
    2012
  • 负责人:
    Sushil Jajodia
  • 依托单位:
SHF: Small: EAGER: Architectural Support for Improving Cloud Computing Security
  • 批准号:
    1037987
  • 项目类别:
    Standard Grant
  • 资助金额:
    $20.0万
  • 财政年份:
    2010
  • 负责人:
    Sushil Jajodia
  • 依托单位:
国内基金
海外基金
Capture and Release of Droplets Using Advanced Materials for High Technology Applications
  • 批准号:
    52073127
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2020
  • 负责人:
    Alidad Amirfazli
  • 依托单位: