首页 | 官方网站   微博 | 高级检索  
     

XML查询的推理审计
引用本文:严和平,刘兵,汪卫,施伯乐.XML查询的推理审计[J].计算机学报,2006,29(8):1308-1317.
作者姓名:严和平  刘兵  汪卫  施伯乐
作者单位:复旦大学计算机与信息技术系,上海,200433
基金项目:国家自然科学基金;国家高技术研究发展计划(863计划)
摘    要:XML文档作为一种网上信息交换方式,其应用越来越广泛.信息发布的安全性给数据库带来新的挑战,目前一些安全策略以法律条文形式颁布,这要求采用有效的手段证实对XML文档的访问与安全策略的一致性.审计能达到这样的目的,但已有的审计方法只能对SQL查询结果进行审计,不能对XML文档查询——XQuery或Xpath进行审计,且蓄意破坏的用户可能通过对查询结果进行推理来访问敏感信息,这就要求对XQuery的审计必然同时具备推理能力.对此,首先提出了可靠而可行的XQuery审计方法、算法及相应查询图模型(QGM);为使审计具备基本的推理能力,针对XML文档的几种典型约束,给出了推理审计方法、算法及相应查询图模型;实验结果表明,给出的XML查询推理审计框架切实可行.

关 键 词:查询  审计  推理
收稿时间:2006-04-04
修稿时间:2006-04-042006-06-01

Inference Auditing the XQuery of XML
YAN He-Ping,LIU Bing,WANG Wei,SHI Bo-Le.Inference Auditing the XQuery of XML[J].Chinese Journal of Computers,2006,29(8):1308-1317.
Authors:YAN He-Ping  LIU Bing  WANG Wei  SHI Bo-Le
Affiliation:Department of Computer and Information Technology, Fudan University, Shanghai 200433
Abstract:XML(eXtensible Markup Language) is rapidly becoming the de facto standard for exchanging data between applications, and publishing data on the Web brings security database new challenges. Privacy principles are even being mandated internationally through legislations and guidelines, and this requires the secure database to verify that it adheres to its declared data disclosure policy. Auditing system satisfies the above desiderata well, but existed auditing system can only be used for SQL query and not fit for the XQuery or Xpath of XML. Moreover only auditing the result of XQuery is not enough, because malicious user can access sensitive information by inferring the result of XQuery. This demands the auditing system have the basic inference capacity. Firstly based on the existed auditing system, the authors propose their XQuery auditing system, and then they add the inference capacity to the audit framework. Their experiment results show the effectiveness and efficiency of the proposed XQuery audit method, algorithm, and the corresponding Query-Graph-Model.
Keywords:XML  XQuery
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号