The Security of Confidential Numerical Data in Databases
Rathindra Sarathy () and
Krishnamurty Muralidhar ()
Additional contact information
Rathindra Sarathy: Department of Management, Oklahoma State University, Stillwater, Oklahoma 74078-4011
Krishnamurty Muralidhar: School of Management, Gatton College of Business & Economics, University of Kentucky, Lexington, Kentucky 40506-0034
Information Systems Research, 2002, vol. 13, issue 4, 389-403
Abstract:
Organizations are storing large amounts of data in databases for data mining and other types of analysis. Some of this data is considered confidential and has to be protected from disclosure. When access to individual values of confidential numerical data in the database is prevented, disclosure may occur when a snooper uses linear models to predict individual values of confidential attributes using nonconfidential numerical and categorical attributes. Hence, it is important for the database administrator to have the ability to evaluate security for snoopers using linear models. In this study we provide a methodology based on Canonical Correlation Analysis that is both appropriate and adequate for evaluating security. The methodology can also be used to evaluate the security provided by different security mechanisms such as query restrictions and data perturbation. In situations where the level of security is inadequate, the methodology provided in this study can also be used to select appropriate inference control mechanisms. The application of the methodology is illustrated using a simulated database.
Keywords: Confidentiality; Data Perturbation; Database Security; Inferential Disclosure; Inferential Security (search for similar items in EconPapers)
Date: 2002
References: View references in EconPapers View complete reference list from CitEc
Citations: View citations in EconPapers (5)
Downloads: (external link)
http://dx.doi.org/10.1287/isre.13.4.389.74 (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:inm:orisre:v:13:y:2002:i:4:p:389-403
Access Statistics for this article
More articles in Information Systems Research from INFORMS Contact information at EDIRC.
Bibliographic data for series maintained by Chris Asher ().