Database label security test method

Zhang Chongbin · Journal of Tsinghua University(Science and Technology) · 2012

Safety evaluations of high-security database management systems(DBMS) need to be guided by an adequate security policy model and a test suite that are automatically generated according to the testing requirements.The access control policy components of the second part of the common criteria and elements of the label security component in current commercial DBMS products,such as the security level,category and group of the mandatory access control(MAC) components,are used to define a database label model based on the finite state mechanism.The system also gives handling mechanisms between various elements of components with read/write policy rules for labeling component elements binding database subjects and database objects.A formal model is gives for a five-tuple automaton for database label security and a graphics-traverse search method to produce a state transition tree and transition sequences for the migration coverage criteria of the five-tuple automaton.W3C State Chart XML(SCXML) is used to describe the five-tuple automaton with a method to process the SCXML of the five-tuple automaton.A security policy example is given for high-security DBMS to illustrate the process to produce the coverage test suite for DBMS security label assessment.

Read the paper · More papers on PaperTik