CSC 405 Introduction to Computer Security. Topic 6.3: Database Inference Control. Outline. Inference attacks Direct attacks (no inference needed) Indirect attacks via aggregations Tracker attacks Inference via linear systems Inference via database constraints Inference control
CSC 405Introduction to Computer Security
Topic 6.3: Database Inference Control
(SEX !=M ^ SEX !=F) (DORM=AYRES)
Sums of Financial Aid by Dorm and Sex
Female Students Living in Grey
Count of Financial Aid by Dorm and Sex
Male Students Living
in Holmes or West
is equivalent to
sum (Sex=F) –
sum ((Sex=F)^(Race!=C Dorm != Holmes)
= ________ – ________ = ______
q(C) is disallowed
C=C1 ^ C2
T=C1 ^ ~C2
Tracker
C
C2
C1
q(C)=q(C1) – q(T)
Student by Dorm and Sex
What are the suppressed values?
Students by Sex and Drug Use