Issue No. 01 - February (1996 vol. 8)
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/69.485629
<p><b>Abstract</b>—The database inference problem is a well-known problem in database security and information system security in general. In order to prevent an adversary from inferring classified information from combinations of unclassified information, a database inference analyst must be able to detect and prevent possible inferences. Detecting database inference problems at database design time provides great power in reducing problems over the lifetime of a database. We have developed and constructed a system called Wizard to analyze databases for their inference problems. The system takes as input a database schema, its constituent instances (if available) and additional human-supplied domain information, and provides a set of associations between entities and/or activities that can be grouped by their potential severity of inference vulnerability. A knowledge acquisition process called microanalysis permits semantic knowledge of a database to be incorporated into the analysis using conceptual graphs. These graphs are then analyzed with respect to inference-relevant domains we call facets using tools we have developed. We can determine inference problems within single facets as well as some inference problems between two or more facets. The architecture of the system is meant to be general so that further refinements of inference information subdomains can be easily incorporated into the system.</p>
Information security, conceptual graphs, database inference, inference detection, inference analysis, transitive associations.
T. H. Hinke and H. S. Delugach, "Wizard: A Database Inference Analysis and Detection System," in IEEE Transactions on Knowledge & Data Engineering, vol. 8, no. , pp. 56-66, 1996.