Proceedings. 1988 IEEE Symposium on Security and Privacy
DOI: 10.1109/secpri.1988.8114
|View full text |Cite
|
Sign up to set email alerts
|

The SeaView security model

Abstract: A formal security policy model that uses basic view concepts for a secure multilevel relational database system is described. The model is formulated in two layers, one corresponding to a security kernel or reference monitor that enforces mandatory security, and the second defining multilevel relations and formalizing policies for labeling new and derived data, data consistency, discretionary security, and transaction consistency. This includes the policies for sanitization, aggregation, and downgrading. The m… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
32
0

Publication Types

Select...
7

Relationship

0
7

Authors

Journals

citations
Cited by 81 publications
(32 citation statements)
references
References 7 publications
0
32
0
Order By: Relevance
“…If an index only plan is selected then the label column is not available and therefore the access rules from the label access policy associated with the table cannot be evaluated. MLS RDBMS extended the primary key on an MLS relation with the security label column in order to allow the simultaneous existence of multiple tuples with the same (non extended) primary key (i.e., polyinstantiation) [1]. We borrow this idea from the MLS work to extend every index created on a labeled table (including the primary key) with the row label column(s).…”
Section: Index-only Access Methodsmentioning
confidence: 99%
See 2 more Smart Citations
“…If an index only plan is selected then the label column is not available and therefore the access rules from the label access policy associated with the table cannot be evaluated. MLS RDBMS extended the primary key on an MLS relation with the security label column in order to allow the simultaneous existence of multiple tuples with the same (non extended) primary key (i.e., polyinstantiation) [1]. We borrow this idea from the MLS work to extend every index created on a labeled table (including the primary key) with the row label column(s).…”
Section: Index-only Access Methodsmentioning
confidence: 99%
“…The Sea View model [1] was the pioneering formal multilevel secure relational database designed to provide mandatory access control. It extended the concept of a database relation to include the security labels.…”
Section: Multilevel Secure Relational Database Modelsmentioning
confidence: 99%
See 1 more Smart Citation
“…As shown, the response time increases as the granularity of labeling scheme becomes 7 To measure the response time of a query, we measured the time to retrieve the selected tuples into a relation; thus, the reported response times here include the time for inserting the selected tuples, in addition to the time for retrieving the tuples. 8 As we had not implemented the query modification algorithm, each query was modified manually before the experiment. Our future work includes a full implementation of the query modification method in a public domain database management system.…”
Section: Methodsmentioning
confidence: 99%
“…Previous work on multilevel secure relational databases [14,4,15,8] also provides many valuable insights for designing a fine-grained secure data model. In a multilevel relational database system, every piece of information is classified into a security level, and every user is assigned a security clearance.…”
Section: Related Workmentioning
confidence: 99%