Show simple item record

dc.contributor.authorSchultz, David
dc.contributor.authorLiskov, Barbara H.
dc.date.accessioned2014-09-22T18:26:38Z
dc.date.available2014-09-22T18:26:38Z
dc.date.issued2013-04
dc.identifier.isbn9781450319942
dc.identifier.urihttp://hdl.handle.net/1721.1/90268
dc.description.abstractNumerous sensitive databases are breached every year due to bugs in applications. These applications typically handle data for many users, and consequently, they have access to large amounts of confidential information. This paper describes IFDB, a DBMS that secures databases by using decentralized information flow control (DIFC). We present the Query by Label model, which introduces new abstractions for managing information flows in a relational database. IFDB also addresses several challenges inherent in bringing DIFC to databases, including how to handle transactions and integrity constraints without introducing covert channels. We implemented IFDB by modifying PostgreSQL, and extended two application environments, PHP and Python, to provide a DIFC platform. IFDB caught several security bugs and prevented information leaks in two web applications we ported to the platform. Our evaluation shows that IFDB's throughput is as good as PostgreSQL for a real web application, and about 1% lower for a database benchmark based on TPC-C.en_US
dc.language.isoen_US
dc.publisherAssociation for Computing Machinery (ACM)en_US
dc.relation.isversionofhttp://dx.doi.org/10.1145/2465351.2465357en_US
dc.rightsCreative Commons Attribution-Noncommercial-Share Alikeen_US
dc.rights.urihttp://creativecommons.org/licenses/by-nc-sa/4.0/en_US
dc.sourceMIT web domainen_US
dc.titleIFDB: Decentralized Information Flow Control for Databasesen_US
dc.typeArticleen_US
dc.identifier.citationDavid Schultz and Barbara Liskov. 2013. IFDB: decentralized information flow control for databases. In Proceedings of the 8th ACM European Conference on Computer Systems (EuroSys '13). ACM, New York, NY, USA, 43-56.en_US
dc.contributor.departmentMassachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratoryen_US
dc.contributor.mitauthorSchultz, Daviden_US
dc.contributor.mitauthorLiskov, Barbara H.en_US
dc.relation.journalProceedings of the 8th ACM European Conference on Computer Systems (EuroSys '13)en_US
dc.eprint.versionAuthor's final manuscripten_US
dc.type.urihttp://purl.org/eprint/type/ConferencePaperen_US
eprint.statushttp://purl.org/eprint/status/NonPeerRevieweden_US
dspace.orderedauthorsSchultz, David; Liskov, Barbaraen_US
dc.identifier.orcidhttps://orcid.org/0000-0002-5914-1866
mit.licenseOPEN_ACCESS_POLICYen_US
mit.metadata.statusComplete


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record