Data and Applications Security and Privacy XXVIII: 28th by Vijay Atluri, Günther Pernul

By Vijay Atluri, Günther Pernul

This booklet constitutes the refereed lawsuits of the twenty eighth IFIP WG 11.3 foreign operating convention on information and purposes safeguard and privateness, DBSec 2014, held in Vienna, Austria, in July 2014. The 22 revised complete papers and four brief papers awarded have been rigorously reviewed and chosen from sixty three submissions. The papers are geared up in topical sections on entry regulate, privateness, networked and cellular environments, information entry, cloud databases, and personal retrieval.

3882, pp. 420–436. Springer, Heidelberg (2006) 15. : Query racing: fast completeness certification of query results. , Jajodia, S. ) Data and Applications Security and Privacy XXIV. LNCS, vol. 6166, pp. 177–192. Springer, Heidelberg (2010) 16. : Verifying completeness of relational query results in data publishing. In: Proceedings of the 2005 ACM SIGMOD International Conference on Management of Data, SIGMOD 2005, pp. 407–418. ACM, New York (2005) 17. : Authenticating query results in edge computing.

In that case, we should be able to choose the best one. Definition 4 (Best goal satisfier). Given the set of mechanisms M = {M1 , · · · , Mn } that can be used to satisfy the defined goal G. Let Ci be the set of violated Specification and Deployment of Integrated Security Policies 29 constraints while applying the mechanism Mi . A mechanism Mj is a best goal satisfier if the following condition holds: ∀i ∈ {1, · · · , n}. |Cj | ≤ |Ci |, where |Ci | is the cardinality of Ci . 3 Third Step: Satisfying the Violated Constraints Once we get the best goal satisfier Mbgs for a defined goal G and the corresponding set of violated security and utility constraints C, the challenge then is to, for each violated security constraint, looking for the properties that can satisfy that constraint.

3 Proposed Approach In our approach, we strive to design a support tool allowing, for a given security policy, selection of the best combination of mechanisms to enforce this security policy. To achieve this goal, we suggest the following methodology : – Using an Epistemic Linear Temporal Logic, we defined an expressive language allowing to formally model a system composed of involved entities and the data on which the security policy should be enforced, and formally express the security policy defined by the security administrators.

