One Method and Implementation of Security-Policy-based Data Protection

ZHANG Xiao,WANG Shan,PENG Zhao-Hui
DOI: https://doi.org/10.3969/j.issn.1002-137X.2007.02.030
2007-01-01
Computer Science
Abstract:Preventing unauthorized access is always one of the main issues to database security,however,internal administrator becomes one threat more and more while facilities like firewall are maturing and widely laid out.A security-policy-based method and its principles are introduced in this paper,which can either defense the external intruders or the leakage of sensitive data because of the administrator(s).We also present several guidelines for cost-based query optimization according to the filter functions of the security policy.The basic analyses show it is feasible to effectively reduce the overhead of security checking by query rewriting and optimization in a query engine.
What problem does this paper attempt to address?