Download:
|
by Ravi S, Sushil Jajodia
http://www.list.gmu.edu/confrnc/ncsc/ps_ver/b90int.ps
Add To MetaCart
Abstract:
Abstract. Our goal in this paper is to answer the following question: what mechanisms are required in a general-purpose multiuser database management system (DBMS) to facilitate the integrity objectives of information systems? We are particularly interested in relational DBMS's. Although existing commercial products fall far short of providing the requisite mechanisms, in principle they can be easily extended to incorporate these mechanisms. In a nutshell our conclusion is that realistic mechanisms do exist. Our principal contribution is to identify these mechanisms, fill in the gaps where none existed and point out where gaps still remain. We have also bridged the terminology and concepts of database and security specialists in a coherent manner. 1
Citations
|
419
|
Cryptography and Data Security
– Denning
- 1982
|
|
357
|
The protection of information in computer systems
– Saltzer, Schroeder
- 1975
|
|
291
|
A comparison of commercial and military computer security policies
– Clark, Wilson
- 1987
|
|
164
|
Notes on data base operating systems
– Gray
- 1978
|
|
129
|
Why do Computers Stop and What Can Be Done About It
– Gray
- 1986
|
|
67
|
Transaction control expressions for separation of duties
– Sandhu
- 1988
|
|
51
|
The schematic protection model: Its definition and analysis for acyclic attenuating schemes
– Sandhu
- 1988
|
|
35
|
Database security and integrity
– Femandez, Summers, et al.
- 1981
|
|
34
|
Formal Models of Capability-Based Protection Systems
– Snyder
- 1981
|
|
28
|
The Schematic Protection Model: Its De nition and Analysis for Acyclic Attenuating Schemes
– Sandhu
- 1988
|
|
26
|
Operating System Structures to Support Security and Reliable
– Linden
- 1976
|
|
26
|
Transformation of access rights
– Sandhu
- 1989
|
|
24
|
Extending the relational database model to capture more meaning
– Codd
- 1979
|
|
14
|
The Source of Authority for Commercial Access Control
– Moffett, Sloman
- 1988
|
|
12
|
Evaluation of model for computer integrity
– Clark, Wilson
- 1998
|
|
11
|
An Introduction to Database Systems. Volume I, Addison-Wesley, fourth edition
– Date
- 1986
|
|
9
|
A Large-Scale Interactive Administrative System
– Wimbrow
- 1971
|
|
8
|
The source of authority for commercial access control
– ett, D, et al.
- 1988
|
|
7
|
Mandatory controls for database integrity
– Sandhu
- 1990
|
|
5
|
Comments on the Integrity Model
– Clark, Wilson
- 1989
|
|
4
|
Data Integrity in a Business Data Processing System
– Murray
- 1987
|
|
4
|
Authorization and Views
– Selinger
- 1980
|
|
2
|
Audit Trail Organization in Relational Databases
– Jajodia, Gadia, et al.
- 1990
|
|
2
|
On the Use of Mandatory
– Murray
|
|
1
|
DBMS Integrity and Secrecy Control
– Burns
- 1989
|