Database inference attack control device and method thereof
Patent Information
- Application Number
- JP2025542274
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2023-02-06
- Filing Date
- 2024-02-05
- Publication Date
- 2026-09-17
- Estimated Expiration
- 2044-02-05
AI Technical Summary
【0034】 本発明は、推論攻撃を構成できる推論攻撃要素及び推論ロジックを設定してDBで質疑語に対する検索結果である結果データから推論攻撃が発生するかを検出し、結果データで推論攻撃を構成できる推論攻撃要素に該当するデータ属性を制限処理するので、推論攻撃による情報漏洩を根本的に遮断できる効果がある。
Smart Images

Figure 0007922982000046 
Figure 0007922982000047 
Figure 0007922982000048
Abstract
Description
[Technical Field]
[0001] The present invention relates to a database (DB) inference attack control device and method thereof, more specifically to a database inference attack control device and method thereof, which can infer personal information by inputting result data output from multiple database management systems (DBMS) that manage one or more DBs, detecting inference attacks that are difficult to detect with access control and query control methods based on pre-configured inference knowledge, analyzing the inference attack in terms of multi-stage risk, and restricting one or more data attributes corresponding to the inference attack elements related to the inference attack before providing them to the inquiryr, thereby preventing sensitive personal information from being inferred and leaked. [Background technology]
[0002] In recent years, information and communication technology has developed rapidly, and web-based services have become widespread and widely used. To provide all of these services, each service provider (SP) needs to manage a large amount of customer information as a database, and based on the information in the database, distributes various knowledge-based content such as finance, shopping, education, and healthcare.
[0003] As customer information is increasingly stored in online databases, the number of hackers attempting to steal this information is on the rise, and cases of large amounts of customer data being extracted from the databases of major service providers are becoming more frequent.
[0004] Typically, service providers apply access control technologies to their service delivery systems to allow and block access to database information based on access control rules, in order to prevent the leakage of database information.
[0005] Furthermore, query control techniques are commonly used to protect database information by controlling queries. Specifically, these query control methods protect key database information by setting and controlling permissions for queries according to various conditions, such as by database user or group, and by prohibiting the execution of queries deemed to be important for security.
[0006] However, existing access control and query control technologies have the problem that they are fundamentally incapable of detecting inference attacks. Inference attacks are attacks that use some publicly available or obtainable data to infer sensitive personal information or other information that should be kept private and protected (hereinafter referred to as "sensitive information").
[0007] To prevent such inference attacks, measures are taken such as not disclosing information that could be used in inference attacks, applying de-identification techniques, or encrypting information stored in databases.
[0008] However, if all information in the database that could be used for inference attacks is kept private, anonymization techniques are applied, or encryption is used, then there is a problem in that the information cannot be utilized.
[0009] Furthermore, this type of technology has limitations in fundamentally preventing inference attacks and in fundamentally defending against inference attacks on inferable knowledge data infrastructure. Here, inferable knowledge data refers to data that is deemed to be obtainable from other sources, socio-engineering, or other means.
[0010] Furthermore, there are problems such as the inability to analyze the multi-stage risk level against inference attacks, the inability to prevent information leaks due to competitive condition inference attacks, and the inability to prevent information leaks due to inference attacks against multiple databases. [Overview of the Initiative] [Problems that the invention aims to solve]
[0011] Therefore, the object of the present invention is to provide a database inference attack control device and method that takes result data output from a database management system (DBMS) that manages a diverse number of DBs as input, detects inference attacks that cannot be detected by access control methods based on inference knowledge, analyzes the inference attack with a multi-level risk assessment, and restricts one or more data attributes related to the inference attack before providing them to the questioner, thereby preventing sensitive information from being inferred. [Means for solving the problem]
[0012] To achieve the above objectives, the database inference attack control device according to the present invention is characterized by including: an input / output unit that receives and outputs question words from a plurality of questioner terminals, receives result data which is a response to the input question words, and provides it to the questioner terminal; one or more databases (DBs) that include a plurality of data attributes, and at least one of the DBs includes sensitive data attributes set for sensitive information to be protected, and searches the DB for question words input from the input / output unit, generates result data which is the search result, and outputs it; and an inference control unit that sets inference knowledge including inference logic composed of inference attack elements and logical operations corresponding to data attributes that can infer the sensitive information, detects an inference attack that can infer the sensitive information from the result data input from the DBMS by referring to the inference logic, restricts data attribute information corresponding to at least one or more inference attack elements that can infer the sensitive information among the inference attack elements included in the result data in which the inference attack was detected, and transmits it to the questioner terminal via the input / output unit.
[0013] The inference control unit includes an inference knowledge storage unit that stores inference knowledge including inference attack elements corresponding to the inference logic and data attributes provided to the questioner terminal unit; an inference setting unit that receives input from a security administrator via the security administrator terminal unit, which allows for the inference of sensitive information configured in the DB, generates inference logic including the one or more data attributes, stores it in the inference knowledge storage unit as inference knowledge, sets the data attributes included in the inference logic as inference attack elements, and outputs inference attack element information including the set inference attack elements; and an inference setting unit that receives and sets inference attack element information from the inference setting unit, extracts inference attack elements corresponding to the inference attack element information from result data input from the DBMS, and generates and outputs an inference attack transaction composed of the extracted inference attack elements. The system is characterized by including: an attack element extraction unit; an inference attack detection unit that receives the inference attack transaction as input and checks whether the inference attack elements included in the inference attack transaction and the inference attack elements already provided to the questioner terminal and stored in the inference knowledge storage unit satisfy any one of the inference logics of the inference knowledge storage unit to detect an inference attack, and outputs restriction processing request information for any one of the inference attack elements of the inference attack transaction when an inference attack is detected; and an inference attack control unit that, when the inference attack detection unit inputs restriction processing request information, restricts the data attribute corresponding to the inference attack element of the input restriction processing request information from the data attribute included in the result data corresponding to the inference attack transaction in which the inference attack was detected, and provides it to the questioner terminal via an input / output unit.
[0014] The inference control unit further includes an inference attack ordering component that sequentially orders and outputs a plurality of inference attack transactions input from the inference attack element extraction unit, and the inference attack detection unit is characterized in that it detects an inference attack using the sequentially ordered inference attack transactions.
[0015] The inference setting unit is characterized by including an inference logic generation unit that receives one or more data attributes that can be used to infer the sensitive information configured in the DB from a security administrator via a security administrator terminal, generates an inference logic that includes the one or more data attributes, and stores it in the inference knowledge storage unit as inference knowledge, and an inference attack element generation unit that sets the data attributes included in the inference logic as an inference attack element and outputs it.
[0016] The inference logic generation unit is characterized by including: an inference attack logic generation unit that receives one or more data attributes from a security administrator via a security administrator terminal that can infer sensitive information in relation to the sensitive information configured in the DB, generates an inference attack logic including the one or more data attributes as one of the inference logics and stores it in the inference knowledge storage unit; and an inferenceable logic generation unit that receives one or more data attributes that can improve the accuracy of the inference attack against the sensitive information, generates an inferenceable logic including the one or more data attributes, combines the inferenceable logic and the inference attack logic to generate an extended inference attack logic, and then stores it in the inference knowledge storage unit as inference knowledge.
[0017] The inference setting unit is characterized in that, when a multi-stage risk setting request is made by a security administrator via the security administrator terminal unit, it selects one or more of the inference attack elements in a non-overlapping manner to generate an inference attack subset, provides it to the security administrator, receives the risk level for each inference attack subset from the security administrator, sets the risk level for each inference attack subset, and stores it in the inference knowledge storage unit as inference knowledge.
[0018] The aforementioned inference setting unit is further characterized in that, when a threshold setting request is received from the security administrator terminal unit, an inference attack element threshold, which is the number of inference attack elements that constitute the inference attack subset to be restricted, is input, and the threshold is set by storing it in the knowledge storage unit.
[0019] The threshold setting unit is characterized in that, when a threshold setting request is received from the security administrator terminal, a risk level threshold, which is the risk level at which restriction processing will be performed on a subset of inference attacks, is further input and set.
[0020] The threshold setting unit is characterized in that, when a threshold setting request occurs, it further sets an inferential logic threshold, which is the number of inferential attack elements to be restricted among the inferential attack elements included in the inferential logic.
[0021] The inference attack detection unit is characterized in that, when determining the inference attack elements to be restricted, it refers to the inference knowledge to determine the inference attack elements to be restricted so as not to be provided to the questioner terminal.
[0022] The inference attack control unit is characterized by performing a masking process, anonymization process, or removal process to remove data attribute information from the result data that corresponds to the inference attack element to be restricted, and then restricting the data attribute information.
[0023] A database inference attack control method according to the present invention for achieving the above-described objectives is characterized by including a database search process in which a database stores information including a plurality of data attributes, and at least one of the databases is managed by one or more DBMSs that manage one or more databases containing sensitive information to be protected, searches for question words input from the databases, generates and outputs result data, and an inference control process in which an inference control unit sets inference knowledge including inference logic composed of inference attack elements and logical operations corresponding to data attributes that can infer the sensitive information, detects an inference attack that can infer the sensitive information from the result data input from the DBMS by referring to the inference logic, restricts data attributes corresponding to at least one or more inference attack elements among the inference attack elements included in the result data in which an inference attack was detected, and transmits it to the questioner terminal via an input / output unit.
[0024] The inference control process includes an inference setting step in which the inference control unit receives one or more data attributes from a security administrator via an inference setting unit that allow it to infer the sensitive information configured in the DB, generates an inference logic including the one or more data attributes and stores it in an inference knowledge storage unit as inference knowledge, sets the data attributes included in the inference logic as inference attack elements, and outputs inference attack element information including the set inference attack elements; an inference attack element extraction step in which the inference control unit receives and sets inference attack element information from the inference setting unit, extracts inference attack elements corresponding to the inference attack element information from result data input from the DBMS, generates and outputs an inference attack transaction composed of the extracted inference attack elements; and an inference control unit receives an inference attack transaction via an inference attack detection unit and outputs the inference attack transaction The system includes: an inference attack detection step that checks whether the inference attack elements included in the transaction and the inference attack elements already provided to the questioner terminal and stored in the inference knowledge storage unit satisfy any one of the inference attack logic, inferenceable logic, and inference attack subset of the inference knowledge storage unit to detect an inference attack, and when an inference attack is detected, outputs restriction processing request information for any one of the inference attack elements of the inference attack transaction; and an inference attack control step that, when the inference control unit receives restriction processing request information from the inference attack detection unit via the inference attack control unit, restricts the data attributes included in the result data corresponding to the inference attack elements of the input restriction processing request information that correspond to the inference attack elements of the input restriction processing request information, and provides them to the questioner terminal via the input / output unit.
[0025] The inference control process further includes an inference attack ordering configuration step in which the inference control unit sequentially orders and outputs a plurality of inference attack transactions input from the inference attack element extraction unit via the inference attack ordering configuration unit, and is characterized in that, in the inference attack control step, when restriction processing request information is input from the inference attack detection unit, the inference attack control unit restricts the data attributes of the result data corresponding to the inference attack elements of the input restriction processing request information among the data attributes of the result data corresponding to the inference attack transaction in which an inference attack was detected, and provides them to the questioner terminal unit via the input / output unit.
[0026] The inference setting step is characterized by including an inference logic generation step in which the inference setting unit receives one or more data attributes from a security administrator via an inference logic generation unit that can infer the sensitive information configured in the DB, generates an inference logic including the one or more data attributes, and stores it in the inference knowledge storage unit as inference knowledge, and an inference attack element generation step in which the inference setting unit sets the data attributes included in the inference logic as an inference attack element via an inference attack element generation unit and outputs it.
[0027] The inference logic generation step is characterized by comprising: a step in which the inference logic generation unit receives one or more data attributes from a security administrator via an inference attack logic generation unit that can infer the sensitive information configured in the DB in relation to the sensitive information, generates an inference attack logic including the one or more data attributes as one of the inference logics, and stores it in the inference knowledge storage unit; and a step in which the inference logic generation unit receives one or more data attributes via an inferable logic generation unit that can improve the accuracy of the inference attack against the sensitive information, generates an inferable logic including the one or more data attributes, combines the inferable logic and the inference attack logic to generate an extended inference attack logic, and then stores it in the inference knowledge storage unit as inference knowledge.
[0028] The inference setting step further includes a multi-stage risk setting step in which, when a multi-stage risk setting request is made by a security administrator via a security administrator terminal via a multi-stage risk setting unit, the inference setting unit generates an inference attack subset composed of one or more inference attack elements selected so as not to overlap and provides it to the security administrator, the security administrator inputs the risk level for each inference attack subset, the risk level for each inference attack subset is set and stored in the inference knowledge storage unit as inference knowledge.
[0029] The inference setting step is characterized in that the inference setting unit, upon receiving a threshold setting request from the security administrator terminal via the threshold setting unit, receives and sets an inference attack element threshold, which is the number of inference attack elements that constitute the inference attack subset to be restricted.
[0030] In the threshold setting step, the inference setting unit is further configured when a threshold setting request is received from the security administrator terminal via the threshold setting unit, and a risk level threshold, which is the risk level at which restriction processing is performed on the inference attack subset, is input.
[0031] In the threshold setting step, the inference setting unit further sets an inferenceable logic threshold, which is the number of inference attack elements among the inferenceable logic's inference attack elements to be restricted, when the threshold setting request occurs via the threshold setting unit.
[0032] In the inference attack detection step, the inference attack control unit determines, by referring to the inference knowledge, which it restricts from being provided to the questioner terminal unit when determining which inference attack elements to restrict.
[0033] The inference attack control step is characterized in that the inference attack control unit performs a masking process, anonymization process, or removal process to remove data attribute information from the result data that corresponds to the inference attack element to be restricted, and restricts the data attribute information. [Effects of the Invention]
[0034] This invention sets inference attack elements and inference logic that can constitute an inference attack, detects whether an inference attack occurs from result data which is the search result for a query term in the DB, and restricts data attributes that correspond to inference attack elements that can constitute an inference attack in the result data, thereby having the effect of fundamentally blocking information leakage due to inference attacks.
[0035] Furthermore, the present invention prevents inference attacks by setting attributes of inferable knowledge data that are determined to be obtainable from other sources, socio-engineering methods, or other means as inference attack elements, and detecting result data that can be included in the inference logic to constitute an inference attack, thereby preventing inference attacks.
[0036] Furthermore, since the present invention serializes simultaneous or parallel inference attacks to detect inference attack elements, it has the effect of detecting race condition inference attacks and preventing information leakage.
[0037] Furthermore, since the present invention detects inference attacks on result data for question words output from multiple DBMSs, it has the effect of detecting and defending against inference attacks on multiple databases. [Brief explanation of the drawing]
[0038] [Figure 1] This diagram shows the configuration of the DB inference attack control device according to the present invention. [Figure 2] This figure shows the configuration of the inference control unit in the DB inference attack control device according to the present invention. [Figure 3] This diagram shows the configuration of the inference setting unit in the inference control unit according to the present invention. [Figure 4] This figure shows an example of a database configuration according to one embodiment of the present invention. [Figure 5] This diagram illustrates how to configure inference logic using one embodiment of the present invention. [Figure 6]This figure shows the elements of an inference attack according to one embodiment of the present invention. [Figure 7] This figure shows a multi-level risk table for different subsets of inference attacks using one embodiment of the present invention. [Figure 8] This figure illustrates a method for configuring serial ordering of inference attacks using concurrent processing of two result data according to one embodiment of the present invention. [Figure 9] This figure illustrates a method for configuring a serial ordering inference attack using parallel processing of two result data according to one embodiment of the present invention. [Figure 10] This is a flowchart showing the DB inference attack control method according to the present invention. [Modes for carrying out the invention]
[0039] The configuration and operation of the DB inference attack control device according to the present invention will be described in detail below with reference to the attached drawings, and the DB inference attack control method in the device will be described.
[0040] The present invention is not limited to these.
[0041] Figure 1 shows the configuration of the DB inference attack control device according to the present invention.
[0042] Referring to Figure 1, the DB inference attack control device of the present invention includes an input / output unit 10, an inference control unit 20, and at least one DBMS 30.
[0043] The input / output unit 10 is either directly connected to the questioner terminals of multiple questioners, or connected via the data communication network 1.
[0044] The aforementioned questioner terminal can transmit question words to the inference control unit 20 using various DB client programs, such as access via the web using HTTP / HTTPS to the input / output unit 10, a DBMS client program, and a proprietary client program.
[0045] The input / output unit 10 receives question words from the questioner terminal and provides them to the inference control unit 20, and the inference control unit 20 receives result data in response to the question words and provides it to the questioner terminal.
[0046] The aforementioned questioner is, for example, an administrator or any user. Therefore, the questioner's terminal unit is, for example, an administrator's terminal unit or a user's terminal unit.
[0047] The aforementioned questioner's terminal unit includes, for example, computer terminals such as desktop computers, personal computers, and notebook computers, as well as mobile terminals such as smartphones and smartpads.
[0048] The aforementioned data communication network 1 is a data communication network that includes, for example, a mobile communication network including 3rd generation (3G), 4G, 5G, etc., a wired or wireless internet network including a local area network (LAN), a wide area network (WAN), and a Wi-Fi network, as well as an intranet network, an extranet network, etc.
[0049] The questioner terminal, input / output unit 10, inference control unit 20, DBMS 30, and DB 40 can be directly connected by wire depending on the various configuration environments, or they can be connected via the data communication network 1 using wired or wireless communication.
[0050] The DBMS 30 includes at least one or more DBs 40, searches the DB 40 for an input question word, generates result data for the question word, and then transmits the result data to the inference control unit 20. The DBMS 30 may be configured to exist in the physically same server as the inference control unit 20, configured to exist in a physically same space via the aforementioned data communication network 1, configured to be physically separated such as in a data center or a cloud environment, or configured as a combination of these forms. The data configured in the DB 40 may be configured in the form of one table, configured as a plurality of tables, or the plurality of tables may be configured in different DBs 40 from each other.
[0051] The result data (r (u、p、q) ) is defined as shown in the following mathematical formula 1.
[0052]
Formula
[0053] Here, r (u、p、q) represents the q-th result data of the DBMS p for the question from the questioner (u), and indicates that it is composed of a set of data d x . Said d x is included in the q-th result data r p of the DBMS (u、p、q) for the questioner (u), and means data ordered according to an inquiry order, a position order, a time order, or the like. For example, if y<z, data d y has priority over data d z in the inquiry order, position order, or time order. D u means a result data set for the questioner (u), and is composed of a set of r (u、p、q) . Dset means a result data set for all questioners, and is composed of a set of D u .
[0054] The inference control unit 20 provides the input query to the corresponding DBMS 30, and each DBMS 30 provides result data (r( u、p、q) ) is entered.
[0055] The inference control unit 20 extracts inference attack elements from the data attributes included in the input result data, which are elements that can constitute an inference attack, determines whether the extracted inference attack elements constitute a pre-configured inference attack logic, and if it is determined that they constitute an inference attack logic, it restricts the data attribute information corresponding to the inference attack element in the result data so that pre-configured sensitive information cannot be inferred, and then provides it to the questioner's questioner terminal via the input / output unit 10. The restriction processing includes, for example, masking or anonymizing the data attribute information corresponding to the inference attack element so that it cannot be identified, or removal processing to remove the data attribute information from the result data.
[0056] Figure 2 shows the configuration of the inference control unit in the DB inference attack control device according to the present invention, Figure 3 shows the configuration of the inference setting unit in the inference control unit according to the present invention, Figure 4 shows an example of DB configuration according to one embodiment of the present invention, Figure 5 is a diagram for explaining the configuration method of the inference logic according to one embodiment of the present invention, and Figure 6 is a diagram showing the inference attack elements according to one embodiment of the present invention. Figure 7 shows a multi-stage risk table by inference attack subset according to one embodiment of the present invention, Figure 8 is a diagram for explaining the inference attack serial ordering configuration method by concurrent processing of two result data according to one embodiment of the present invention, and Figure 9 is a diagram for explaining the inference attack serial ordering configuration method by parallel processing of two result data according to one embodiment of the present invention. The following explanation will be given with reference to Figures 2 to 9, but the explanation will be given using the configuration of DB 40 as shown in Figure 4 as an example.
[0057] First, we will describe the table configuration in DB40 according to one embodiment of the present invention.
[0058] DB40 data can be structured into a single table 401 containing multiple records, each with its own data attribute. Figure 4 shows a table containing 12 records, each with 7 data attributes. Alternatively, DB40 data, although having 7 attributes, can also be structured by splitting it into multiple tables.
[0059] In Figure 4, Table 401 consists of 12 records, each having seven data attributes defined for each data attribute (patient name, age, address, zip code, treatment, surgery, cancer).
[0060] In the example in Figure 4, cancer data attribute information is set as sensitive information to be protected. It is assumed that query results containing questions or content that directly access cancer data attributes are blocked and cannot be obtained by normal protection methods such as question word restrictions and access control. Therefore, the questioner cannot directly obtain information about the data attribute "cancer" from DB40.
[0061] The inference control unit 20 includes an inference setting unit 110, multiple inference attack element extraction units 120 that receive result data from each of the multiple DBMSs 30, an inference attack sequencing configuration unit 130, an inference attack detection unit 140, an inference knowledge storage unit 150, an inference attack control unit 160, and an inference attack log storage unit 170.
[0062] The inference setting unit 110 includes an inference logic setting interface unit 210, an inference logic generation unit 220, an inference attack element generation unit 230, a multi-stage risk level setting unit 240, and a threshold setting unit 250.
[0063] The inference logic setting interface unit 210 connects to the security administrator terminal unit either directly or via the input / output unit 10.
[0064] The inference logic setting interface unit 210 provides an inference logic setting means to the connected security administrator terminal, enabling it to check the data attributes of tables configured in DB40 via DBMS30 and data attributes corresponding to sensitive information using the inference logic setting means, and provides setting means for each inference logic setting element, enabling it to make settings for the said inference logic setting element.
[0065] The aforementioned inference logic setting elements include, for example, inference attack logic, inferenceable logic, multi-level risk assessment, and thresholds.
[0066] The inference logic generation unit 220 generates inference logic including the inference attack logic generation unit 221 and the inferable logic generation unit 222, and then stores it in the inference knowledge storage unit 150 via the inference attack detection unit 140, or stores it directly in the inference knowledge storage unit 150.
[0067] The inference attack logic generation unit 221 generates inference attack logic by receiving data attributes that can directly infer sensitive information from among the data attributes excluding data attributes corresponding to sensitive information configured in the DB 40, via setting means for inference attack logic setting elements provided to the security administrator terminal unit via the inference logic setting interface unit 210. The logical operation may be input by the security administrator or may be pre-set. The logical operation may be, for example, and, or, not, >, =, <, etc., and the set logical operation expression may consist of a single logical operation (for example, A and B) or be applied in a complex manner (for example, not(A and B)).
[0068] The aforementioned inference attack logic can be defined as shown in Equation 2 below, and an example configuration will be illustrated with reference to 501 in Figure 5.
[0069]
number
[0070] Here, α x is the inference attack logic, and A is the inference attack logic (α x It is a set of ).
[0071] Inference attack logic (α x ) consists of one or more data attributes.
[0072] Figure 5, item 501, shows the inference attack logic (α) in the example DB configuration in Figure 4. x This shows that, if the names of patients who have cancer are considered sensitive information, then this shows an inference attack logic consisting of patient name, treatment, and surgery, which are data attributes that can directly infer the names of patients who have cancer. In other words, in the case of 501 in Figure 5, the inference attack logic (α w , α x ) can be expressed as shown in equation 3 below.
[0073]
number
[0074] Here, α w This was previously an inference attack logic, α x is, α w The following is the inference attack logic, where ∧ represents the logical operator AND.
[0075] To explain further, the inference attack logic α of the above formula 3 w This means that it is an inference attack that can be inferred that a patient (Z) who has undergone immunotherapy (X) and tumor removal surgery (Y) is a patient with cancer.
[0076] The inference attack logic generation unit 221 generates the inference attack logic α w It is generated and stored in the inference knowledge storage unit 150 as one of the inference knowledge.
[0077] Here, we assume that control has been added to prevent the acquisition of information about the patient data attribute, which is identification information. Therefore, the inference attack logic α of formula 3 does not include the controlled data attribute patient. x This can be generated and stored in the inference knowledge storage unit 150 as one of the inference knowledge. In this way, the patient of the data attribute is controlled, so the inference attack logic α w and α x The effective inference attack element included is the identical inclusion of two data attributes: treatment and surgery. Therefore, in the following explanation, we will refer to the inference attack logic α. x I will explain based on that.
[0078] Since the questioner cannot directly obtain information about the patient and cancer data attributes in Figure 4, the inference attack logic α x This makes it impossible to accurately infer whether a particular patient has cancer. In other words, it is not possible to determine whether a particular person has cancer based solely on immunotherapy (X) and tumor removal (Y) information.
[0079] Taking Figure 4 as an example, records 1, 5, 8, 9, and 12 in Table 401 correspond to cases where immunotherapy was received and tumor removal surgery was performed. However, since information about the data attributes patient and cancer cannot be obtained, while the fact that cancer was contracted can be inferred, it is not possible to know who the patient was.
[0080] Therefore, in order to identify patients with cancer and make accurate inferences, the inference attack logic (α x Further inference attack elements not included in ) are required. Therefore, the inference logic generation unit 222 receives input from the security administrator terminal unit via the inference logic setting interface unit 210 that one or more data attributes which it determines can be used to improve the accuracy of inference attacks against sensitive information in DB40 are input to the inference logic (c xThis generates the inferable logic, which can be defined as shown in Equation 4 below. A configuration example is illustrated with reference to Figure 5, 502.
[0081]
number
[0082] Here, c x C represents the set of inferable logic that is deemed usable to improve the accuracy of inferential attacks against sensitive information.
[0083] Figure 5, item 502, shows the inferable logic (c) in the DB configuration example in Figure 4. x This shows that, if the patient name with cancer is sensitive information, it shows an inferable logic consisting of age and address, which are data attributes that can be used to infer the patient name with cancer. That is, in the case of 502 in Figure 5, the inferable logic (c x ) can be expressed as shown in equation 5 below.
[0084]
number
[0085] Here, A represents age, and B represents address information.
[0086] To explain in more detail, as mentioned above, immunotherapy and tumor removal information alone does not tell us who is a cancer patient.
[0087] Furthermore, age and address information alone do not determine whether a patient has cancer.
[0088] Furthermore, age, address, and immunotherapy information alone do not determine whether a patient has cancer. For example, in Figure 4, James (No. 1) and Oliver (No. 10), both 26 years old and residing in Seattle, both received immunotherapy, but Oliver did not develop cancer.
[0089] Furthermore, age, address, and tumor removal information alone do not determine whether a patient has cancer. For example, in Figure 4, John (No. 5) and Rebecca (No. 7), both aged 35 and residing in San Francisco, both underwent tumor removal surgery, but Rebecca did not have cancer.
[0090] However, if all information such as age, address, immunotherapy, and tumor removal is obtained, it becomes possible to determine whether a particular person is a cancer patient. That is, the patient's name can be determined in relation to the age and address information (for example, people living in the patient's residential area can know the patient's name and age, and can indirectly know the patient's name and age through people living in the patient's residential area, as well as through a combination of information obtained from other sources). Then, by correlating the age and address information thus obtained with the immunotherapy and tumor removal information, it can be inferred that the patient with the aforementioned name is a cancer patient.
[0091] Therefore, when the inferable logic is generated, the inferable logic (c x ) to the aforementioned inference attack logic α w and α x The (extended) inference attack logic α shown in Figure 5, 503, and the following equation 6, which was applied and extended, is shown. w and α x It generates and stores it in the inference knowledge storage unit 150.
[0092]
number
[0093] The inference attack element generation unit 230 receives the inference attack logic generated from the inference logic generation unit 220, along with one or more of the inferable logic and extended inference attack logic, and sets a data attribute consisting of the inference attack logic and one or more of the inferable logic and extended inference attack logic as shown in Figure 6, into the inference attack element.
[0094] The inference attack element generation unit 230 provides the inference attack element extraction unit 120 with inference attack element information (or "inference attack element set," (E)), which is information about the configured inference attack elements. Depending on the embodiment, the inference attack element information (E) may be provided to the security administrator terminal unit via the inference logic setting interface unit 210, or to the multi-stage risk level setting unit 240. The inference attack element information (E) can be represented by the following formula 7.
[0095]
number
[0096] Here, e i is an inference attack element, and E represents the set of inference attack elements.
[0097] Taking Figure 6 as an example, e1=patient, e2=age, e3=addr, e i =treatment, e j =Surgery
[0098] When a multi-stage risk setting request is made by a security administrator via the security administrator terminal unit, the multi-stage risk setting unit 240 receives inference attack elements from the inference attack element generation unit 230 and sets an inference attack subset (s x ) generates an inference attack subset (s x As shown in Figure 7, one or more inference attack elements (e) included in the inference attack element information are iIt consists of ) and no order is assigned to the inference attack elements included in the inference attack subset.
[0099] As shown in Figure 7, the multi-stage risk setting unit 240 provides the security administrator terminal unit with a multi-stage risk table including a subset of inference attacks via the inference logic setting interface unit 210. At this time, the risk level field is, for example, a null value.
[0100] The multi-stage risk level setting unit 240 receives risk levels from the security administrator via the security administrator terminal unit for each inferred attack subset of the multi-stage risk level table, sets the risk level values, and stores the multi-stage risk level table with the set risk level values in the inferred knowledge storage unit 150. The risk levels can be divided into low < medium < high < very high (critical), as shown in Figure 7. The multi-stage risk level table in Figure 7 can be represented by the following formula 8.
[0101]
number
[0102] Here, s x This is a subset of inference attacks, v x This represents a danger level. And V stands for multi-level danger table.
[0103] Taking Figures 6 and 7 as examples, if a multi-level risk level is set to (s3, v3) = ({e2, e3}, medium), then (s3, v3) = ({age(A)), add(B)}, medium). This means that if a subset of inference attacks is detected that includes inference attack elements that can obtain information about the patient's age (A) and address (B), the risk level is medium.
[0104] As another example, (s5, v5) = ({e1, e jIf a multi-level risk level is set to}, high, then (s5, v5) is ({patient(Z), surgery(Y)}, high), so the risk level is high if a subset of inference attacks is detected that includes inference attack elements that can obtain the patient's name (Z) and information about tumor removal (i.e., Y = tumor removal).
[0105] Another example is (s6, v6) = ({e i , e j If a multi-level risk level is set for}, critical, then (s6, v6) is ({treatment(X), surgery(Y)}, critical), meaning that the risk is very high (critical) if a subset of inference attacks is detected that includes inference attack elements that can obtain information about the patient's immunotherapy and tumor removal (i.e., X = immunotherapy, Y = tumor removal).
[0106] The threshold setting unit 250 receives thresholds from the security administrator for the inference attack elements to be restricted from the result data input from the DBMS 30, and stores them in the inference knowledge storage unit 150 for setting. The thresholds are divided into three types: inference attack element threshold (ρ), danger level threshold (σ), and inferenceable logic threshold (τ), and one or more thresholds can be applied.
[0107] The inference attack element threshold (ρ) is the extracted inference attack elements, i.e., the inference attack subset (s x This is the number of inference attack elements that are restricted by ), and is defined as shown in equation 9 below.
[0108]
number
[0109] len() is a subset of inference attacks (s xThis means a function that returns the number of elements in ). Therefore, the inference attack element threshold (ρ) is the inference attack subset (s x It is set to a positive integer value that is the same as or smaller than the number of elements in ).
[0110] In other words, the inference attack element threshold (ρ) is the inference attack subset (s x If it is determined that an inference attack corresponding to ) has occurred, the inference attack subset (s x This is used to control inference attacks so that they do not succeed by restricting the disclosure of information about a number of inference attack elements that meet the threshold among the inference attack elements that make up the system.
[0111] For example, suppose the inference attack threshold (ρ) is set to 1, and the inference attack subset is s x ={e i , e j Assuming} = {treatment(X), surgery(Y)}, len(s x Since )=2, the two elements that make up the inference attack subset are the inference attack elements, e i , e j The system restricts access to information that matches one of the criteria, preventing it from being publicly disclosed and thus controlling the system to prevent inference attacks from succeeding.
[0112] The inference attack elements corresponding to the aforementioned inference attack element threshold (ρ) are selected from the earliest order based on the input time, selected from the latest order and restricted, or selected randomly and restricted.
[0113] The danger level threshold (σ) is defined as shown in equation 10 below.
[0114]
number
[0115] Here, v x This indicates the level of danger.
[0116] Therefore, the danger level threshold (σ) can be set to one of the following danger levels (low, medium, high, or critical), and the level value can be set using any one of the following notations: numbers, letters, or symbols that indicate the magnitude and severity of the grade.
[0117] For example, if the danger level threshold (σ) = high, then the inference attack subset {e1, e i}, {e1, e j}, {e i , e j When} is detected, all inference attack elements in that inference attack subset are restricted from being exposed. Restricting all inference attack elements in that inference attack subset in this way reduces the usability of the data.
[0118] Furthermore, when the risk level threshold and the inference attack element threshold are applied in combination according to other embodiments, if an inference attack subset with a risk level corresponding to or higher than the set risk level threshold is detected, a restriction process is performed to prevent the disclosure of a number of inference attack elements within that subset that correspond to the inference attack element threshold ρ. Therefore, instead of restricting the disclosure of all inference attack elements, the restriction process is performed to prevent the disclosure of a number of inference attack elements that correspond to the inference attack element threshold (ρ). Thus, by not restricting the disclosure of all inference attack elements, but only restricting the disclosure of a number of inference attack elements that correspond to the inference attack element threshold (ρ), the purpose of inference control can be achieved, and the effect of improving data usability can be achieved.
[0119] The inferable logic threshold (τ) is defined as shown in equation 11 below.
[0120]
number
[0121] Here, c x `<element>` represents the inferable logic, and `len()` represents the function that returns the number of elements in the inferable logic.
[0122] As shown in equation 11 above, the inferable logic threshold (τ) is the inferable logic subset (c x It is set to a non-negative integer value that is less than the number of elements in the element.
[0123] The inferable logic threshold (τ) is used to restrict information about the inferable logic element corresponding to the inferable logic threshold (τ) from being disclosed when it is determined that an inferable logic inferable logic has occurred. The inferable logic element corresponding to the inferable logic threshold (τ) is restricted by selecting from the earliest order based on the input time, selecting from the latest order, or selecting randomly.
[0124] As described above, the inference attack element threshold (ρ), the danger level threshold (σ), and the inferable logic threshold (τ) may be set individually or in combination of two or more. Therefore, by appropriately setting these three types of thresholds in combination and applying restriction processing, it is possible to prevent sensitive information from being leaked through inference attacks while simultaneously improving data usability.
[0125] The security administrator can connect to the inference logic setting interface unit 210 via the security administrator terminal unit and add, delete, and modify the inference attack logic and inferable logic described above, add, delete, and modify the risk levels in the multi-level risk table, and add, delete, and modify thresholds. Furthermore, the security administrator can change the values of each threshold.
[0126] The inference attack element extraction unit 120 is set by receiving inference attack element information input from the inference setting unit 110, and receives result data (r (u、p、q) ), which is search result data for a question from an arbitrary questioner, input from the DBMS 30. After extracting data attribute information corresponding to an inference attack element of the inference attack element information from the input result data, the inference attack element extraction unit generates an inference attack transaction (t (u、p、q) ) that includes the inference attack element corresponding to the extracted data attribute, and outputs the generated inference attack transaction to the inference attack ordering construction unit 130. The inference attack transaction is defined as the following Mathematical Formula 12.
[0127]
NUM
[0128] Here, t (u、p、q) represents the q-th inference attack transaction on the DBMS p by an arbitrary questioner (u), and is formed of a set of inference attack elements φ x . φ x is an inference attack element included in the q-th inference attack transaction (t p ) on the DBMS (u、p、q) by an arbitrary questioner (u), and is included in inference attack element information (E). The inference attack element (φ x ) is an inference attack element ordered according to an inquiry order, a position order, a time order or the like. That is, for times y and z, if y<z, the inference attack element φ y has priority over the inference attack element φ z . Tset represents a set of inference attack transactions attempted by all questioners, and is formed of a set of all T u . T u represents an inference attack transaction set by an arbitrary questioner (u), and is formed of a set of t (u、p、q) .
[0129] An inference attack transaction in which extracted inference attack elements are serialized in order can be defined as the following Mathematical Formula 13.
[0130]
Num.
[0131] Here, JPEG0007922982000014.jpg86 represents a serializable inference attack transaction, and in the DBMS by any querier (u) p the q-th inference attack transaction set (T u = {t (u、p、q)}) is included. Then, JPEG0007922982000015.jpg77 represents a serially ordered inference attack transaction set as a set of JPEG0007922982000016.jpg87. Therefore, for times y and z, if y<z, the inference attack transaction JPEG0007922982000017.jpg88 has priority over the inference attack transaction JPEG0007922982000018.jpg78.
[0132] FIG. 8 shows the first result data (r p1 ) for queriers a and b input to the inference attack element extraction unit 120 from the same DBMS and the inference attack elements of the second result data (r (a、p1、q1 ) (b、p1、q2) occurring and input concurrently, and FIG. 9 shows a case where they occur and input in parallel.
[0133] A more specific description with reference to FIGS. 8 and 9 is as follows: the inference attack elements e j and e i of querier a, and the inference attack elements e i and e j of result data for querier b occur simultaneously or in parallel relative to each other in terms of timing and are input to the inference attack element extraction unit 120.
[0134] At this time, the inference attack element extraction unit 120 prioritizes e that is earlier in timing with respect to the result data of querier aj and e i , inferential attack transaction t in this order (a、p1、q1) ={φ1=e j , φ2=e i}={φ1=surgery(Y), φ2=treatment(X)} is output to the inferential attack sequencing component 130.
[0135] Further, the inferential attack element extraction unit 120 prioritizes time with respect to the result data of querier b, e i and e j , inferential attack transaction t in this order (b、p1、q2) ={φ1=e i , φ2=e j}={φ1=treatment(X), φ2=surgery(Y)} is output to the inferential attack sequencing component 130.
[0136] The inferential attack sequencing component 130 receives inferential attack transactions t (a、p1、q1) and t (b、p1、q2) and result data r (a、p1、q1) and r (b、p1、q2) When input time information of is input, as shown in FIG. 8 and FIG. 9, regardless of the input time points of the inferential attack elements, the result data r (a、p1、q1) and r (b、p1、q2) according to the input time order of JPEG0007922982000019.jpg96=t (b、p1、q2) and JPEG0007922982000020.jpg97=t (a、p1、q1) is serialized in this order and output to the inferential attack detection unit 140. In other words, the inferential attack transaction JPEG0007922982000021.jpg97=t (b、p1、q2) is the inferential attack transaction JPEG0007922982000022.jpg86=t (a、p1、q1) , which means it is prioritized in terms of time compared to.
[0137] This method serializes all inferential attack transactions output from all inferential attack element extraction units 120 and outputs the serialized transactions to the inferential attack detection unit 140.
[0138] When the inference attack detection unit 140 receives serially ordered inference attack transactions from the inference attack ordering configuration unit 130, it determines, according to the embodiment, which of the input inference attack transactions is inferable logic (c x The inference attack detection unit 140 detects inference attack transactions that include ) and determines the inference attack elements that are restricted by the set inference threshold (τ). In addition, the inference attack detection unit 140 identifies an inference attack subset (s) from the input inference attack transactions. x The system detects inference attack transactions that constitute the inference attack, analyzes the risk level by referring to the multi-level risk table of the inference knowledge storage unit 150 according to the embodiment, determines whether it is an inference attack subset that falls above a set risk level threshold, and determines the inference attack elements to be restricted.
[0139] Once the inference attack elements to be restricted are determined, the inference attack detection unit 140 generates restriction processing request information including the inference attack elements to be restricted and outputs it to the inference attack control unit 160.
[0140] The inference attack element threshold (ρ) is set to 1, the danger level threshold (σ) is set to very high (critical), and the inference logic threshold (τ) is set to 1. The inference attack logic, age(A)∧addr(B))∧treatment(X)∧surgery(Y), is applied to the sequentially ordered inference attack transaction. JPEG0007922982000023.jpg96=[age(A), addr(B)] is entered first, followed by a serially ordered inference attack transaction. JPEG0007922982000024.jpg95 and Let's take the example of when JPEG0007922982000025.jpg87 is entered.
[0141] The inference attack detection unit 140 detects the previously input serially ordered inference attack transactions. Inferable logic in JPEG0007922982000026.jpg88 (c xSince it is detected that )=age(A)∧addr(B) has occurred, one of age(A) and addr(B) is selected and restricted by the set inferable logic threshold (τ=1). In this embodiment, the inference attack detection unit 140 detects the inference attack transaction In the case of JPEG0007922982000027.jpg88=[age(A), addr(B)], one of the addr(B) values that is in the latest order is restricted, and the remaining age(A) values are determined to be provided to the questioner. The determined content is then stored as inference knowledge in the inference knowledge storage unit 150.
[0142] The inference attack detection unit 140 then processes the input inference attack transactions, which are sequentially ordered. JPEG0007922982000028.jpg86 and The first thing entered in JPEG0007922982000029.jpg87 JPEG0007922982000030.jpg77=t (b、p1、q2) =[φ1=e i φ2=e j Determine if ]=[φ1=treatment(X), φ2=surgery(Y)] matches a subset of inference attacks with a very high (critical) danger level threshold (σ). Based on the result of the determination, the inference attack transaction JPEG0007922982000031.jpg86 is an inference attack subset s6={e i , e j Since it matches to}, the inference attack detection unit 140 selects one of treatment(X) or surgery(Y) and restricts it based on the set inference attack element threshold (ρ=1). In this embodiment, the inference attack detection unit 140 detects the inference attack transaction JPEG0007922982000032.jpg85=[treatment(X), surgery(Y)] The surgery(Y) that is in the latest order is to be restricted, and the remaining treatment(X) is to be provided to the questioner, and the content of the above determination is stored as inference knowledge in the inference knowledge storage unit 150.
[0143] And the already occurring inference attack elements age(A) and addr(B) The inference attack elements φ1=treatment(X) and φ2=surgery(Y) in JPEG0007922982000033.jpg86 are in the inference attack logic (α x Since it constitutes a system, the inference attack detection unit 140 notifies the security administrator terminal that an inference attack has occurred and provides reporting information regarding its contents.
[0144] Thus, the inference attack detection unit 140 detects the inference attack logic (c x ) and inference attack subset (s x When it detects that a configuration has been established, it determines which inference attack elements to restrict according to the threshold, generates restriction processing request information including information about the determined inference attack elements, and provides it to the inference attack control unit 160.
[0145] As a result, the inference attack detection unit 140 detects the inference attack transaction Entered after JPEG0007922982000034.jpg86 JPEG0007922982000035.jpg87 is also a subset of inference attacks s6={e i , e j Since it matches}, inference attack transaction One of the two inference attack elements in JPEG0007922982000036.jpg76 must be restricted. The inference attack detection unit 140 refers to the inference knowledge stored in the inference knowledge storage unit 150, The system generates restriction processing request information that requests restriction processing for the same inference attack elements as those restricted in JPEG0007922982000037.jpg86 and provides it to the inference attack control unit 160.
[0146] Here, different DBMSs p1 and DBMS p2Inference attack originating from transaction t (a、p1、q1) and t (b、p2、q2) And the resulting data r (a、p1、q1) and r (b、p2、q2) In this case, it is clear that inference control is performed as described above. Also, different DBMSs are accessed by the same user (a). p1 and DBMS p2 Inference attack originating from transaction t (a、p1、q1) and t (a、p2、q2) And the resulting data r (a、p1、q1) and r (a、p2、q2) In this case as well, it is clear that inference control is performed, as described above.
[0147] The above description explains the case where thresholds are applied in combination, but if only the danger level threshold (very high (critical)) is set, the inference attack detection unit 140 will use the inference attack logic s x Restriction processing request information is generated and provided to the inference attack control unit 160, requesting that restriction processing be performed on all of them.
[0148] As another example, let's assume that the inference attack element threshold is set to 1, the inferable logic threshold is set to 0, and the danger level threshold (σ) is set to very high (critical).
[0149] In this case, the inference attack detection unit 140 detects the previously input serially ordered inference attack transactions. For JPEG0007922982000038.jpg88, the system determines that both age(A) and addr(B) can be provided to the questioner according to the inferable logic threshold (τ=0), and stores this as inferred knowledge in the inferred knowledge storage unit 150. Then, the inferred attack detection unit 140 processes the previously input inferred attack transaction. JPEG0007922982000039.jpg98 is a subset of inference attacks s6={e i , e j It is determined that it matches}.
[0150] Therefore, the inference attack detection unit 140, according to the set inference attack element threshold (ρ=1) In this embodiment, one of the inference attack elements of JPEG0007922982000040.jpg88, either treatment(X) or surgery(Y), is selected and restricted. In this embodiment, one of the later-order surgery(Y) is determined to be the inference attack element to be restricted, and the inference attack element to be restricted and the provided inference attack elements are stored as inference knowledge in the inference knowledge storage unit 150, and the inference attack transaction Restriction processing request information for JPEG0007922982000041.jpg88 is generated and provided to the inference attack control unit 160. Then, the already occurring inference attack elements {age(X), addr(Y)} and the inference attack transaction are processed. The inference attack elements treatment(X) and surgery(Y) of JPEG0007922982000042.jpg88 are inferred to be x Since it determines that a ) has occurred, the inference attack detection unit 140 notifies the security administrator terminal that an inference attack has occurred and provides reporting information regarding the matter.
[0151] Then, the inference attack detection unit 140 detects the inference attack transaction Entered after JPEG0007922982000043.jpg87 For JPEG0007922982000044.jpg76, the restriction process is determined in the same way as in the previous example, the determined content is stored as inference knowledge in the inference knowledge storage unit 150, inference attack log information is generated and stored in the inference attack log storage unit 170, and the inference attack transaction Restriction processing request information for JPEG0007922982000045.jpg76 is generated and provided to the inference attack control unit 160.
[0152] Furthermore, the inference attack detection unit 140 outputs restriction processing request information to the inference attack control unit 160, requesting that result data that does not constitute an inference attack logic be output without restriction processing.
[0153] The inference attack control unit 160 receives result data from the DBMS 30, and restrictive processing request information for each result data. If there are no inference attack elements that have been restricted according to the input restrictive processing request information, the unit provides the result data to the questioner terminal as is via the input / output unit 10, or it restricts the data attributes corresponding to the inference attack elements that have been restricted according to the restrictive processing request information, and then provides the result data to the questioner terminal.
[0154] The aforementioned restriction process may involve masking or anonymizing the data attribute information of the result data, or removing the data attribute information from the result data.
[0155] Figure 10 is a flowchart showing the DB inference attack control method according to the present invention.
[0156] Referring to Figure 10, the inference control unit 20 provides an inference logic setting interface means to the security administrator terminal via the inference setting unit 110 to set the inference logic, and stores the set inference logic as inference knowledge in the inference knowledge storage unit 150 (S111). The inference logic setting consists of setting the inference attack logic, inferable logic, extended inference attack logic, inference attack element threshold (ρ), multi-stage danger level threshold (σ), and inferable logic threshold (τ).
[0157] Once the inference logic is set, the inference control unit 20 generates inference attack elements using the inference attack logic, inferenceable logic, and extended inference attack logic generated via the inference attack element generation unit 230 of the inference setting unit 110, and generates inference attack element information (E) for the inference attack elements and provides it to the inference attack element extraction unit 120 (S113).
[0158] Once the inference logic is set and the inference attack elements are configured, the inference control unit 20 monitors whether result data is input from the DBMS 30 via the inference attack element extraction unit 120 (S115).
[0159] When result data is input, the inference control unit 20 checks whether each inference attack element of the pre-configured inference attack element information is included in the result data via the inference attack element extraction unit 120, and if it is included, extracts the inference attack element and generates an inference attack transaction (t) composed of the extracted inference attack element. (u、p、q) After generating the ), it is output to the inference attack ordering configuration unit 130 (S117).
[0160] The aforementioned inference attack transaction (t (u、p、q) When input is received, the inference control unit 20 receives the inference attack transaction (t) input from the multiple inference attack element extraction unit 120 via the inference attack ordering configuration unit 130. (u、p、q) The results are sequentially ordered from earliest to latest input time and output to the inference attack detection unit 140 (S119).
[0161] The inference control unit 20 checks whether the inference attack elements of the serially ordered inference attack transactions input from the inference attack ordering configuration unit 130 via the inference attack detection unit 140 match the inferable logic and the inference attack subset (S121). If the inference attack elements of the input inference attack transactions do not match the inferable logic and the inference attack subset, the inference attack detection unit 140 transmits restriction processing request information to the inference attack control unit requesting that the result data be output without restriction processing, and the inference attack control unit 160 provides the result data to the questioner terminal unit without restriction processing (S123).
[0162] When the occurrence of an inference attack transaction that matches the inferenceable logic and inference attack subset is detected, the inference control unit 20, via the inference attack detection unit 140, determines that the inference attack elements included in the inference attack transaction that correspond to a threshold are to be restricted as inference attack elements (S125). At this time, the inference attack detection unit 140 refers to the previously restricted inference attack elements stored in the inference knowledge storage unit 150, determines whether there are any previously restricted inference attack elements among the inference attack elements corresponding to the threshold, and if there are, determines that the previously restricted inference attack elements are to be restricted with the result data corresponding to the current inference attack transaction.
[0163] Once the inference attack elements to be restricted are determined, the inference control unit 20 determines, via the inference attack detection unit 140, whether there are any inference knowledge update elements (S127). That is, the inference attack detection unit 140 determines whether to restrict them or whether there are any new inference attack elements to be provided to the questioner.
[0164] If a new restriction process is applied or a new inference attack element is provided, the inference attack detection unit 140 updates the inference knowledge by storing the inference attack element as inference knowledge in the inference knowledge storage unit 150 (S129).
[0165] The inference attack detection unit 140 determines whether the inference attack elements that have already occurred and the inference attack elements of the input inference attack transaction constitute an inference attack logic (S131). If it determines that an inference attack logic has been established, it notifies the security administrator terminal that an inference attack has occurred and provides reporting information regarding the matter (S133).
[0166] The inference control unit 20, via the inference attack control unit 160, restricts data attribute information that corresponds to the inference attack element that has been decided to be restricted among the multiple data attributes that constitute the result data (S135).
[0167] The inference control unit 20 provides the questioner terminal unit via the input / output unit 10 the result data that has been restricted via the inference attack control unit 160 (S137).
[0168] The inference attack control unit 160 generates an inference attack log that includes the detection and restriction processing results of the inference attack, and stores the generated inference attack log in the inference attack log storage unit 170 (S139).
[0169] In the embodiment described above, as shown in Figure 4, a single table containing multiple records having seven data attributes was used as an example. However, it is obvious that the inference attack control method according to the present invention can also be applied to result data containing the results of querying a view, even in other cases where the questioner approaches a view and asks a question.
[0170] Furthermore, when a questioner uses a question word that modifies a data attribute name (for example, ALTER, RENAME, SELECT AS, etc.), it is desirable that the inference control unit 20 transmits modification information, including the original data attribute name and the modified data attribute name corresponding to the original data attribute name, to the inference setting unit 110 when the question word is input via the input / output unit 10, and modifies the inference attack logic, inferable logic, and extended inference attack logic in accordance with the modified data attribute name.
[0171] Specifically, the inference control unit 20 adds or updates the modified data attribute name corresponding to the original data attribute name (S111), generates or updates further inference attack elements, further sets or updates the inference attack element information (E) and the multi-stage risk table by inference attack subset to include the further generated or updated inference attack elements (S111), and provides the further generated or updated inference attack elements to the inference attack element extraction unit 120 (S113). As a result, the inference control unit 20 extracts inference attack elements from the data attributes included in the result data that correspond to the original data attribute name and the modified data attribute name, and detects and controls the inference attack as described above for the embodiment. Furthermore, when a questioner asks a question via a stored procedure or trigger that includes a question word that modifies the data attribute name, the inference attack is detected and controlled in the same way based on the inference attack elements corresponding to the original data attribute name and the modified data attribute name, as described above for the embodiment. Therefore, it is clear that the inference attack control method according to the present invention can be similarly applied when setting aliases for the names of database-related objects such as tables, views, and procedures using synonyms (or similar methods) and then asking questions. [Explanation of Symbols]
[0172] 10 Input / output section 20 Inference Control Unit 30 Database Management Systems (DBMS) 40 Databases (DB) 110 Inference Setting Unit 120 Inference Attack Element Extraction Unit 130 Inference Attack Sequencing Components 140 Inference Attack Detection Unit 150 Inference Knowledge Storage Unit 160 Inference Attack Control Unit 170 Inference Attack Log Storage Unit 210 Inference Logic Setting Interface Section 220 Inference Logic Generation Unit 221 Inference Attack Logic Setting Section 222 Inferential Logic Generation Unit 230 Inference Attack Element Generation Unit 240 Multi-stage risk level setting unit 250 Threshold setting section
Claims
1. An input / output unit receives and outputs question words from multiple questioner terminals, receives result data which is a response to the input question words, and provides it to the questioner terminal. A database management system (DBMS) comprising at least one database (DB) containing multiple data attributes, at least one of which contains sensitive data attributes set for sensitive information to be protected, and which searches the DB for a query word input from the input / output unit, generates result data which is the search result, and outputs it. A DB inference attack control device is characterized by including: an inference knowledge set including an inference logic composed of an inference attack element corresponding to a data attribute that can infer the sensitive information and a logical operation; an inference control unit that detects an inference attack that can infer the sensitive information from result data input from the DBMS by referring to the inference logic; a restriction process that restricts data attribute information corresponding to at least one or more inference attack elements among the inference attack elements included in the result data in which an inference attack was detected; and a transmission to the questioner terminal unit via the input / output unit.
2. The inference control unit, An inference knowledge storage unit stores inference knowledge including inference attack elements corresponding to the inference logic and data attributes provided to the questioner terminal, An inference setting unit receives one or more data attributes from a security administrator via a security administrator terminal unit that allow for the inference of sensitive information configured in the DB, generates an inference logic including the one or more data attributes and stores it in the inference knowledge storage unit as inference knowledge, sets the data attributes included in the inference logic as inference attack elements, and outputs inference attack element information including the set inference attack elements. An inference attack element extraction unit receives and sets inference attack element information from the inference setting unit, extracts inference attack elements corresponding to the inference attack element information from the result data input from the DBMS, and generates and outputs an inference attack transaction composed of the extracted inference attack elements. An inference attack detection unit receives the aforementioned inference attack transaction as input and checks whether the inference attack elements included in the inference attack transaction and the inference attack elements already provided to the questioner terminal stored in the inference knowledge storage unit satisfy any one of the inference logics of the inference knowledge storage unit to detect an inference attack. When an inference attack is detected, the inference attack detection unit outputs restriction processing request information to any one of the inference attack elements of the inference attack transaction. The DB inference attack control device according to claim 1, further comprising: an inference attack control unit that, upon input of restriction processing request information from the inference attack detection unit, restricts data attributes among the data attributes included in the result data corresponding to the inference attack transaction in which an inference attack was detected, the data attributes corresponding to the inference attack elements of the input restriction processing request information, and provides them to the questioner terminal unit via an input / output unit.
3. The inference control unit, The system further includes an inference attack ordering component that sequentially orders and outputs a plurality of inference attack transactions input from the inference attack element extraction component, The aforementioned inference attack detection unit, The DB inference attack control device according to claim 2, characterized in that it detects an inference attack using the serially ordered inference attack transactions.
4. The inference setting unit, An inference logic generation unit receives one or more data attributes from a security administrator via a security administrator terminal that allow for the inference of the sensitive information configured in the DB, generates an inference logic that includes the one or more data attributes, and stores it in the inference knowledge storage unit as inference knowledge. The DB inference attack control device according to claim 2, characterized in that it includes an inference attack element generation unit that sets data attributes included in the inference logic as inference attack elements and outputs them.
5. The inference logic generation unit, An inference attack logic generation unit receives one or more data attributes from a security administrator via a security administrator terminal that can infer the sensitive information configured in the DB in relation to the sensitive information, generates an inference attack logic that includes the one or more data attributes as one of the inference logics, and stores it in the inference knowledge storage unit. The DB inference attack control device according to claim 4, comprising: an inference logic generation unit that receives one or more data attributes that can improve the accuracy of an inference attack against the sensitive information as input, generates an inferenceable logic that includes the one or more data attributes, combines the inferenceable logic and the inference attack logic to generate an extended inference attack logic, and then stores it in the inference knowledge storage unit as inference knowledge.
6. The inference setting unit, The DB inference attack control device according to claim 5, further comprising a multi-stage risk setting unit that, when a multi-stage risk setting request is made by a security administrator via a security administrator terminal unit, selects one or more of the inference attack elements in a non-overlapping manner to generate an inference attack subset, provides it to the security administrator, receives the risk level for each inference attack subset from the security administrator to set the risk level for each inference attack subset, and stores it in the inference knowledge storage unit as inference knowledge.
7. The inference setting unit, The DB inference attack control device according to claim 6, further comprising a threshold setting unit that, when a threshold setting request is received from the security administrator terminal unit, receives an inference attack element threshold, which is the number of inference attack elements that constitute the inference attack subset to be restricted, and stores and sets it in the knowledge storage unit.
8. The threshold setting unit is, The DB inference attack control device according to claim 7, characterized in that when a threshold setting request is made from the security administrator terminal, a danger level threshold, which is the danger level at which restriction processing is performed on a subset of inference attacks, is further input and set.
9. The threshold setting unit is, The DB inference attack control device according to claim 7 or 8, characterized in that, when the threshold setting request occurs, an inference logic threshold is further set, which is the number of inference attack elements to be restricted from among the inference attack elements included in the inference logic.
10. The aforementioned inference attack detection unit, The DB inference attack control device according to claim 2, characterized in that when determining the inference attack elements to be restricted, the inference attack elements to be restricted are determined by referring to the inference knowledge so as not to be provided to the questioner terminal.
11. The inference attack control unit, The DB inference attack control device according to claim 2, characterized in that it performs masking, anonymization, or removal processing to remove data attribute information from the result data that corresponds to the inference attack elements to be restricted, and restricts the data attribute information.
12. The database stores information containing multiple data attributes, but at least one of the databases includes a database search process in which one or more DBMSs that manage one or more databases containing sensitive information to be protected perform a search on query terms input from the database, generate result data, and output it. A DB inference attack control method characterized by including an inference control unit that sets inference knowledge including inference logic composed of inference attack elements and logical operations corresponding to data attributes that can infer the sensitive information, a referencing inference logic to detect an inference attack that can infer the sensitive information from result data input from the DBMS, restricts data attributes corresponding to at least one of the inference attack elements included in the result data in which the inference attack was detected, and transmits it to the questioner terminal via the input / output unit.
13. The aforementioned inference control process is The inference control unit receives one or more data attributes from a security administrator via the inference setting unit that allow it to infer the sensitive information configured in the DB, generates an inference logic including the one or more data attributes and stores it in the inference knowledge storage unit as inference knowledge, sets the data attributes included in the inference logic as inference attack elements, and outputs inference attack element information including the set inference attack elements. The inference control unit receives and sets inference attack element information from the inference setting unit, extracts inference attack elements corresponding to the inference attack element information from the result data input from the DBMS, and generates and outputs an inference attack transaction composed of the extracted inference attack elements in the inference attack element extraction step. The inference control unit receives the inference attack transaction via the inference attack detection unit, and detects an inference attack by checking whether the inference attack elements included in the inference attack transaction and the inference attack elements already provided to the questioner terminal and stored in the inference knowledge storage unit satisfy any one of the inference attack logic, inferenceable logic, and inference attack subset of the inference knowledge storage unit, and when an inference attack is detected, outputs restriction processing request information for any one of the inference attack elements of the inference attack transaction. The DB inference attack control method according to claim 12, characterized in that the inference control unit, upon receiving restriction processing request information from the inference attack detection unit via the inference attack control unit, performs restriction processing on data attributes among the data attributes included in the result data corresponding to the inference attack transaction in which an inference attack was detected, which correspond to the inference attack element of the input restriction processing request information, and provides this to the questioner terminal unit via the input / output unit.
14. The aforementioned inference control process is The inference control unit includes an inference attack ordering configuration step in which it sequentially orders and outputs a plurality of inference attack transactions input from the inference attack element extraction unit via the inference attack ordering configuration unit, The DB inference attack control method according to 13, characterized in that, in the inference attack control step, when restriction processing request information is input from the inference attack detection unit, the data attributes of the result data corresponding to the inference attack element of the input restriction processing request information among the data attributes of the result data corresponding to the inference attack transaction in which an inference attack was detected, are restricted and provided to the questioner terminal via the input / output unit.
15. The aforementioned inference setting step is, The inference setting unit receives one or more data attributes from a security administrator via the inference logic generation unit that can infer the sensitive information configured in the DB, generates an inference logic that includes the one or more data attributes, and stores it in the inference knowledge storage unit as inference knowledge. The DB inference attack control method according to claim 13, characterized in that the inference setting unit includes an inference attack element generation step of setting data attributes included in the inference logic as inference attack elements and outputting them via the inference attack element generation unit.
16. The aforementioned inference logic generation step is: The inference logic generation unit receives one or more data attributes from a security administrator via the inference attack logic generation unit that can infer the sensitive information configured in the DB in relation to the sensitive information, and generates an inference attack logic including the one or more data attributes as one of the inference logics and stores it in the inference knowledge storage unit. The DB inference attack control method according to claim 15, characterized in that the inference logic generation unit receives one or more data attributes that can improve the accuracy of an inference attack against the sensitive information via an inferenceable logic generation unit, generates an inferenceable logic that includes the one or more data attributes, combines the inferenceable logic and the inference attack logic to generate an extended inference attack logic, and then stores it in the inference knowledge storage unit as inference knowledge.
17. The aforementioned inference setting step is, The DB inference attack control method according to claim 16, further comprising a multi-stage risk setting step in which, when a multi-stage risk setting request is made by a security administrator via a security administrator terminal via a multi-stage risk setting unit, the inference setting unit generates an inference attack subset composed of one or more inference attack elements selected so as not to overlap and provides it to the security administrator, the security administrator inputs a risk level for each inference attack subset, the risk level for each inference attack subset is set and stored in the inference knowledge storage unit as inference knowledge.
18. The aforementioned inference setting step is, The DB inference attack control method according to claim 17, further comprising a threshold setting step in which the inference setting unit receives a threshold setting request from the security administrator terminal unit via the threshold setting unit, and sets an inference attack element threshold, which is the number of inference attack elements that constitute the inference attack subset to be restricted.
19. The DB inference attack control method according to claim 18, characterized in that in the threshold setting step, when the inference setting unit receives a threshold setting request from the security administrator terminal unit via the threshold setting unit, a danger level threshold, which is the danger level at which the inference attack subset will be restricted, is further input and set.
20. The DB inference attack control method according to claim 18 or 19, characterized in that in the threshold setting step, the inference setting unit further sets an inferenceable logic threshold, which is the number of inference attack elements to be restricted among the inference attack elements of the inferenceable logic, when the threshold setting request occurs via the threshold setting unit.
21. The DB inference attack control method according to claim 13, characterized in that, in the inference attack detection step, when the inference attack control unit determines the inference attack elements to be restricted, it refers to the inference knowledge to determine the inference attack elements to be restricted so as not to be provided to the questioner terminal.
22. The DB inference attack control method according to claim 13, characterized in that in the inference attack control step, the inference attack control unit performs a masking process, anonymization process, or removal process to remove data attribute information corresponding to the inference attack element to be restricted from the result data, and restricts the data attribute information.
Citation Information
Patent Citations
Security device for attribute coupling
JP1995253989A
Data readout management program, system, and method
JP2004110122A
Access control system, access controller, access control method, program and recording medium
JP2005182707A
System and method for anonymized statistical database query
JP2017204277A
Providing data privacy in computer networks using personally identifiable information by inference control
US20170277908A1