Probabilistic logic-based database inference attack control device and method
The database inference attack control device uses probability logic to detect and restrict inference attacks, addressing the real-time detection gap in existing technologies and ensuring data privacy by calculating risk probabilities and processing sensitive data attributes.
Patent Information
- Application Number
- PCT/KR2024/021006
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-28
- Filing Date
- 2024-12-24
- Publication Date
- 2025-07-03
AI Technical Summary
Existing access control and query control technologies in database management systems are unable to detect probabilistic logic-based inference attacks in real time, allowing hackers to infer sensitive information by combining publicly available or obtainable probabilistic knowledge and inferable knowledge data, leading to potential data leaks.
A database inference attack control device and method that employs probability logic to detect and restrict inference attacks by calculating risk probabilities for sensitive information inference, using a probability inference control unit to process and mask or anonymize data attributes based on predefined thresholds and logic models.
Effectively prevents the inference of sensitive information by detecting and blocking probabilistic inference attacks in real time, enhancing data privacy while maintaining usability, and preventing information leakage.
Smart Images

Figure KR2024021006_03072025_PF_FP_ABST
Abstract
Description
Device and method for controlling database inference attacks based on probability logic
[0001] The present invention relates to a device and method for controlling a database (DB) inference attack, and more particularly, to a database inference attack based on a probability logic, which receives result data output from a database management system (DBMS), restricts data attributes corresponding to inference attack elements that are preset to have a more sensitive effect than other inference attack elements in inferring sensitive information from each result data record constituting the result data by a threshold value of a sensitive inference attack element, calculates a risk probability for inferring sensitive information based on a preset probability inference attack logic, determines that an inference attack has been detected if the calculated risk probability exceeds a risk judgment threshold, restricts one or more of the data attributes corresponding to inference attack elements related to the inference attack, and restricts data attributes corresponding to inference attack elements constituting the inferenceable logic based on a preset inferenceable logic that can be used for an inference attack in addition to the probability inference attack logic, by a threshold value of an inferenceable logic, thereby ensuring privacy so that sensitive information cannot be inferred, while increasing data usability of each result data record. It relates to control devices and methods.
[0002] Recently, information and communication technology has rapidly developed, and online services have become widely available and used. To provide all these services, each service provider (SP) must manage a massive amount of customer information in a database. Based on this database information, they distribute a variety of knowledge-based content, including financial, shopping, education, and medical services.
[0003] As customer information is stored in online databases, the number of hackers attempting to steal customer information stored in the database is increasing, and cases of large amounts of customer information being leaked from the databases of large service providers are occurring frequently.
[0004] Typically, service providers apply access control technology to their service provision systems to allow and block access to DB information based on access control rules to prevent information from being leaked from the DB.
[0005] Additionally, query control methods are commonly used to control queries to protect database information. Specifically, the query control method protects key database information by setting and controlling query permissions based on various conditions, such as by DB user or group, and prohibiting the execution of queries deemed critical for security purposes.
[0006] However, existing access control and query control technologies fundamentally impede detection of inference attacks. These inference attacks use publicly available or obtainable data to infer other information (hereinafter referred to as "sensitive information") that is sensitive or should be kept private.
[0007] To prevent such inference attacks, technologies such as preventing the disclosure of information that could be used for inference attacks, applying de-identification technology, or encrypting information stored in the database are being applied.
[0008] However, these types of technologies cannot detect in real time probability logic-based inference attacks, and have limitations in using them to ensure the necessary level of data usability while protecting sensitive information from inference and leakage from probability logic-based inference attacks detected in real time.
[0009] Furthermore, there are inherent limitations in fundamentally defending against inference attacks based on inferable knowledge data. Inferable knowledge data, in this context, refers to data that can be obtained from other sources, social engineering, or other means. In other words, there are limitations in fundamentally preventing inference attacks that combine data retrieved from databases and other sources with already publicly available probabilistic knowledge and statistical information related to sensitive information to probabilistically infer sensitive information that should be kept private.
[0010] Therefore, there is a need for a method to fundamentally prevent database inference attacks that combine publicly available or obtainable probabilistic knowledge and statistical information with inferable knowledge data. Furthermore, measures are needed to control inference based on probabilistic logic to prevent relatively sensitive data from being leaked first.
[0011] Accordingly, the purpose of the present invention is to provide a device and method for controlling a database inference attack based on probability logic, which receives all result data output from a database management system (DBMS) that manages a different number of DBs, a plurality of DB management systems that are remotely operated separately from each other, and DB management systems that are operated in different cloud systems, and detects a probability logic-based inference attack that cannot be detected by an access control method, a query control method, anonymization method, and a technology that processes or encrypts information stored in a DB privately based on probability logic-based inference knowledge, responds to an inference attack that can be performed by combining publicly available or obtainable probabilistic knowledge and statistical information with inferable knowledge data, and provides at least one of the data attributes related to the inference attack with a restriction process to a queryer so as to prevent relatively sensitive data from being leaked first, thereby making it impossible to infer sensitive information.
[0012] In order to achieve the above-described purpose, a database inference attack control device based on probability logic according to the present invention comprises: an input / output unit for receiving and outputting queries from a plurality of query terminals, and receiving result data as a response to the inputted query and providing the result data to the corresponding query terminal; one or more DBMSs having at least one database (DB) including a plurality of data attributes, wherein at least one of the DBs includes a sensitive data attribute set as sensitive information to be protected, and searching the DB for a query input from the input / output unit, and generating and outputting result data as a search result; And it is characterized by including a probability inference control unit that sets inference knowledge including inference attack elements corresponding to data attributes that can probabilistically infer the sensitive information and a probability model composed of the probability of the inference attack elements, probability logic and probability inference attack logic, and calculates a risk probability that the sensitive information can be inferred by inference attack elements extracted from result data input from the DBMS with reference to the inference knowledge, and if the calculated risk probability exceeds a risk judgment threshold, determines that an inference attack has been detected, and restricts and processes data attribute information corresponding to at least one inference attack element that can infer the sensitive information among the inference attack elements included in the result data in which the inference attack has been detected, and then transmits the data attribute information to the corresponding query terminal through the input / output unit.
[0013] The above-mentioned probability inference control unit comprises: an inference knowledge storage unit that stores inference knowledge including inference attack elements corresponding to the probabilistic inference attack logic and data attributes provided to the query terminal; an inference setting unit that receives from a security manager through a security manager terminal one or more data attributes capable of probabilistically inferring the sensitive information configured in a DB and a probability value for a data attribute having a probability of inferring the sensitive information among the data attributes, generates a probability model including the one or more data attributes and probabilities, probability logic, and probabilistic inference attack logic, and stores them as inference knowledge in the inference knowledge storage unit, sets data attributes included in the probabilistic inference attack logic as inference attack elements, and outputs an inference attack element set including the set inference attack elements; an inference attack element extraction unit that receives and sets an inference attack element set from the inference setting unit, extracts inference attack elements corresponding to the inference attack element set from result data input from DBMSs, and generates and outputs an inference attack transaction comprised of the extracted inference attack elements; A probabilistic inference attack detection unit that receives the above-mentioned inference attack transaction as input, constructs an inference attack element check set including inference attack elements included in the above-mentioned inference attack transaction and inference attack elements provided to the query terminal stored in the above-mentioned inference knowledge storage unit, checks whether the inference attack elements of the above-mentioned inference attack element check set satisfy any one of the probabilistic inference attack logics of the above-mentioned inference knowledge storage unit, calculates a risk probability that the sensitive information can be inferred by inference attack elements extracted from the above-mentioned inference attack element check set with reference to the probabilistic inference attack logic, determines that an inference attack has been detected if the calculated risk probability exceeds a risk judgment threshold, and outputs restriction processing request information requesting restriction processing for any one or more of the inference attack elements of the corresponding inference attack transaction when the inference attack is detected;And it is characterized by including a probability inference attack control unit that, when inputting restriction processing request information from the above probability inference attack detection unit, restricts and processes data attributes corresponding to the inference attack elements of the input restriction processing request information among the data attributes included in the result data corresponding to the inference attack transaction in which the inference attack is detected, and provides the data attributes to the corresponding query terminal through the input / output unit.
[0014] The above-mentioned probability inference control unit further includes an inference attack ordering component that serially orders and outputs a plurality of inference attack transactions input from the inference attack element extraction unit, and the above-mentioned probability inference attack detection unit is characterized in that it detects an inference attack by the serially ordered inference attack transactions.
[0015] The above-mentioned inference setting unit is characterized by including an inference logic generation unit that receives from a security manager through a security manager terminal one or more data attributes capable of inferring the sensitive information configured in a DB and a probability value for a data attribute having a probability of inferring the sensitive information among the data attributes, and generates a probability model, probability logic, and probability inference attack logic including the one or more data attributes and probabilities and stores them as inference knowledge in the inference knowledge storage unit; and an inference attack element generation unit that sets a data attribute included in the probability inference attack logic as an inference attack element and outputs it.
[0016] The above-mentioned inference logic generation unit is characterized by including a probability logic generation unit that receives from a security manager through a security manager terminal one or more data attributes that are directly related to the sensitive information configured in a DB and can infer the sensitive information, receives a probability of inferring the sensitive information from the one or more data attributes, and generates a probability logic and a probability calculation value for the probability logic based on a probability model and a conditional probability for each data attribute, and stores the probability logic and the probability calculation value for the probability logic in an inference knowledge storage unit; a probability inference attack logic generation unit that generates a probability inference attack logic including the probability logic generated by the probability logic generation unit as one of the inference knowledge, and stores the probability inference attack logic in the inference knowledge storage unit; and an inferenceable logic generation unit that receives one or more data attributes that can increase the accuracy of an inference attack on the sensitive information, generates an inferenceable logic including the one or more data attributes, generates an extended inference attack logic by combining the inferenceable logic and the probability inference attack logic, and then stores the extended inference attack logic as inference knowledge in the inference knowledge storage unit.
[0017] The above inference setting unit is characterized in that it further includes a sensitive inference attack subset setting unit that receives, from a security manager through a security manager terminal, an inference attack element that has a more sensitive effect on inferring the sensitive information than other inference attack elements among the inference attack elements of the probability inference attack logic, and registers and sets the inference attack element as a sensitive inference attack subset.
[0018] The above inference setting unit detects an inference attack by a probability inference attack logic when a threshold setting request is made from a security manager terminal, and a sensitive inference attack element threshold (ρ), which is the number of inference attack elements to be limitedly processed among inference attack elements when detecting the sensitive inference attack subset. x) and a threshold setting unit that receives an inferential logic threshold (τ), which is the number of inferential attack elements to be limited among the inferential attack elements of the inferential logic when detecting the inferential logic, and stores it in the inferential knowledge storage unit and sets it.
[0019] The above probability inference attack detection unit generates the inference attack element check set including the inference attack elements included in the inference attack transaction record and the previously provided inference attack elements stored in the inference knowledge storage unit for each inference attack transaction record constituting the inference attack transaction, and if a set of inference attack elements corresponding to a sensitive inference attack subset exists in the inference attack element check set, the sensitive inference attack element threshold (ρ) x ) determines the sensitive inference attack elements to be restricted, and stores the sensitive inference attack elements determined to be restricted in the inference knowledge storage as the sensitive inference attack elements that have already been restricted, and removes the sensitive inference attack elements that have already been restricted from the inference attack element check set generated thereafter, and the threshold value (ρ) of the sensitive inference attack elements is used. x) determines a sensitive inference attack element to be newly restricted, removes the sensitive inference attack element to be restricted from the inference attack element check set, removes the sensitive inference attack element to be restricted from the inference attack element check set and the inference attack element common to the probability inference attack logic, and calculates a target set of inference attack element determination, calculates a risk probability that the sensitive information can be inferred by the inference attack elements constituting the probability inference attack logic based on the inference attack element check set, and if the calculated risk probability exceeds the risk judgment threshold (λ), it is considered that an inference attack has been detected, and decides to restrict one of the inference attack elements of the target set of inference attack elements, and updates by removing the inference attack elements that have been decided to be restricted from the inference attack element check set and the inference attack element determination target set, and calculates a risk probability based on the updated inference attack element check set, but until the calculated risk probability does not exceed the risk judgment threshold, the inference attack element It is characterized by determining one of the inference attack elements of the decision target set as the inference attack element to be restricted.
[0020] The above-mentioned probability inference attack detection unit is characterized in that it determines whether the above-mentioned probability inference attack element check set includes inference attack elements that constitute inference-capable logic, and if it is determined that inference-capable logic is constituted, it determines inference attack elements to be restricted and processed among the inference attack elements that constitute the inference-capable logic according to the inference-capable logic threshold (τ).
[0021] The above-mentioned probability inference attack detection unit calculates a risk probability that the sensitive information can be inferred by the inference attack elements constituting the probability inference attack logic based on the inference attack element check set from which the sensitive inference attack elements to be restricted have been removed, wherein the risk probability is calculated in real time when the inference attack is detected, or the probability for the probability logic is calculated in advance based on the conditional probability for each probability model and data attribute and stored in the inference knowledge storage unit, and when the inference attack is detected, the pre-stored probability calculation value corresponding to the probability inference attack logic is output from the inference knowledge storage unit for reference based on the inference attack element check set.
[0022] The above probability inference attack control unit is characterized in that it restricts the data attribute information by performing masking or anonymization processing on the data attribute information corresponding to the inference attack element to be restricted among the result data, or performing removal processing to remove the data attribute information from the result data.
[0023] In order to achieve the above-described purpose, a method for controlling a database inference attack based on probability logic according to the present invention comprises: a DB search process in which one or more DBMSs managing at least one DB containing sensitive information to be protected among one or more DBs storing information including a plurality of data attributes perform a search for a query word input from the DB and generate and output result data according to the search results; And the probability inference control unit sets inference knowledge including inference attack elements corresponding to data attributes from which the sensitive information can be probabilistically inferred and a probability model composed of the probability of the inference attack elements, probability logic and probability inference attack logic, and calculates a risk probability that the sensitive information can be inferred by inference attack elements extracted from result data input from the DBMS with reference to the inference knowledge, and determines that an inference attack has been detected if the calculated risk probability exceeds a risk judgment threshold, and restricts and processes data attributes corresponding to at least one or more inference attack elements from which the sensitive information can be inferred among the inference attack elements included in the result data from which the inference attack has been detected, and transmits the data to the corresponding query terminal through the input / output unit.
[0024] The above-mentioned probability inference control process comprises an inference setting step in which the probability inference control unit receives, from a security manager terminal unit through an inference setting unit, one or more data attributes capable of probabilistically inferring the sensitive information configured in a DB, and a probability value for a data attribute having a probability of inferring the sensitive information among the data attributes, generates a probability model, probability logic, and probability inference attack logic including the one or more data attributes and probabilities, stores them as inference knowledge in an inference knowledge storage unit, sets the data attributes included in the probability inference attack logic as inference attack elements, and outputs a set of inference attack elements including the set inference attack elements; an inference attack element extraction step in which the probability inference control unit receives the set of inference attack elements from the inference setting unit, inputs the set of inference attack elements into an inference attack element extraction unit, sets the set of inference attack elements, extracts inference attack elements corresponding to the set of inference attack elements from result data input from DBMSs through the inference attack element extraction unit, and generates and outputs an inference attack transaction composed of the extracted inference attack elements; A probabilistic inference attack detection step in which the probabilistic inference control unit receives the inference attack transaction through the probabilistic inference attack detection unit, checks whether the inference attack elements of the inference attack element check set including the inference attack elements included in the inference attack transaction and the inference attack elements provided to the query terminal stored in the inference knowledge storage unit satisfy any one of the probabilistic inference attack logics of the inference knowledge storage unit, calculates a risk probability that the sensitive information can be inferred by the inference attack elements of the inference attack element check set with reference to the probabilistic inference attack logic, and determines that an inference attack has been detected if the calculated risk probability exceeds a risk judgment threshold, and outputs restriction processing request information requesting restriction processing for any one or more of the inference attack elements of the corresponding inference attack transaction when the inference attack is detected;And it is characterized in that it includes a probability inference attack control step in which the probability inference control unit, when inputting the restriction processing request information from the probability inference attack detection unit through the probability inference attack control unit, restricts and processes the data attributes corresponding to the inference attack elements of the input restriction processing request information among the data attributes included in the result data corresponding to the inference attack transaction in which the inference attack is detected, and provides the data attributes to the corresponding query terminal through the input / output unit.;
[0025] The above-mentioned probability inference control process further includes an inference attack ordering configuration step in which the probability inference control unit serially orders and outputs a plurality of inference attack transactions input from the inference attack element extraction unit through the inference attack ordering configuration step, and the probability inference attack control unit restricts and processes data attributes corresponding to inference attack elements of the input restriction processing request information among data attributes of the result data corresponding to inference attack transactions in which an inference attack is detected when inputting restriction processing request information from the probability inference attack detection unit in the above-mentioned probability inference attack control step, and provides the data attributes to the corresponding query terminal through the input / output unit.
[0026] The above-described inference setting step is characterized in that the inference setting unit includes an inference logic generation step in which the inference setting unit receives, from a security manager terminal unit through an inference logic generation unit, one or more data attributes capable of inferring the sensitive information configured in the DB and a probability value for a data attribute having a probability of inferring the sensitive information among the data attributes, and generates a probability model, probability logic, and probability inference attack logic including the one or more data attributes and probabilities and stores the data attributes as inference knowledge in the inference knowledge storage unit; and an inference attack element generation step in which the inference setting unit sets data attributes included in the probability inference attack logic as inference attack elements and outputs the data attributes through an inference attack element generation unit.
[0027] The above-mentioned inference logic generation step is a probability logic generation step in which the inference logic generation unit receives, through the probability logic generation unit, from the security manager terminal unit one or more data attributes that are directly related to the sensitive information configured in the DB and can infer the sensitive information, receives a probability of inferring the sensitive information from the one or more data attributes, and generates a probability logic and a probability calculation value for the probability logic based on a probability model and a conditional probability for each data attribute, and stores the generated probability logic in the inference knowledge storage unit; a probability inference attack logic generation step in which the inference logic generation unit generates, through the probability inference attack logic generation unit, a probability inference attack logic including the probability logic generated by the probability logic generation unit as one of the inference knowledge, and stores the generated probability in the inference knowledge storage unit; And it is characterized by including an inference logic generation step in which the inference logic generation unit receives one or more data attributes that can increase the accuracy of an inference attack on the sensitive information through the inference logic generation unit, generates an inference logic including the one or more data attributes, and generates an extended inference attack logic by combining the inference logic and the probability inference attack logic, and then stores the extended inference attack logic as inference knowledge in the inference knowledge storage unit.
[0028] The above inference setting step is characterized in that the inference setting unit further includes a sensitive inference attack subset setting step in which, through a sensitive inference attack subset setting unit, the security manager terminal unit receives, from among the inference attack elements of the probability inference attack logic, an inference attack element that has a more sensitive effect on inferring the sensitive information than other inference attack elements, and registers and sets the inference attack element as a sensitive inference attack subset.
[0029] The above inference setting step is, when the inference setting unit requests threshold setting from the security manager terminal, the threshold setting unit sets a risk judgment threshold (λ) for detecting an inference attack by a probability inference attack logic, and a sensitive inference attack element threshold (ρ), which is the number of inference attack elements to be limitedly processed among inference attack elements when detecting the sensitive inference attack subset. x ) and a threshold setting step of receiving an inferential logic threshold (τ), which is the number of inferential attack elements to be limited among the inferential attack elements of the inferential logic when detecting the inferential logic, and storing it in the inferential knowledge storage unit and setting it.
[0030] The above-mentioned probability inference attack detection step is a step in which the probability inference attack detection unit generates the above-mentioned inference attack element check set including the inference attack elements included in the above-mentioned inference attack transaction record and the previously provided inference attack elements stored in the above-mentioned inference knowledge storage unit for each inference attack transaction record constituting the above-mentioned inference attack transaction, and if a set of inference attack elements corresponding to a sensitive inference attack subset exists in the above-mentioned inference attack element check set, the above-mentioned sensitive inference attack element threshold (ρ) x ) determines the sensitive inference attack elements to be restricted, and stores the sensitive inference attack elements determined to be restricted in the inference knowledge storage as the sensitive inference attack elements that have already been restricted, and removes the sensitive inference attack elements that have already been restricted from the inference attack element check set generated thereafter, and the threshold value (ρ) of the sensitive inference attack elements is used. x) to determine a new sensitive inference attack element to be restricted; an inference attack detection step in which the probabilistic inference attack detection unit removes the sensitive inference attack element to be restricted from the inference attack element check set, and removes the sensitive inference attack element to be restricted from the inference attack element check set and the inference attack element common to the probabilistic inference attack logic to produce an inference attack element determination target set, and calculates a risk probability that sensitive information can be inferred based on the inference attack element check set, and considers an inference attack to be detected if the calculated risk probability exceeds the risk judgment threshold (λ); And when the probability inference attack detection unit determines that the inference attack has been detected, it is characterized by including a first restricted inference attack element determination step of determining one of the inference attack elements of the inference attack element determination target set to be restricted, removing and updating the inference attack elements determined to be restricted from the inference attack element check set and the inference attack element determination target set, and calculating a risk probability based on the updated inference attack element check set, and determining one of the inference attack elements of the inference attack element determination target set as the inference attack element to be restricted until the calculated risk probability does not exceed the risk judgment threshold.
[0031] The above-mentioned probability inference attack detection step is characterized in that the probability inference attack detection unit further includes a second restricted inference attack element determination step in which the probability inference attack detection unit determines whether the inference attack element check set includes inference attack elements constituting the inference possible logic, and if it is determined that the inference possible logic is configured, determines inference attack elements to be restricted among the inference attack elements constituting the inference possible logic according to the inference possible logic threshold (τ).
[0032] The above-described probabilistic inference attack detection step is characterized in that, in calculating the risk probability that the sensitive information can be inferred by the inference attack elements constituting the probabilistic inference attack logic based on the inference attack element check set in which the sensitive inference attack elements to be restricted are removed by the probabilistic inference attack detection unit, the risk probability is calculated in real time when the inference attack is detected, or the probability for the probability logic is calculated in advance based on the conditional probability for each probability model and data attribute and stored in the inference knowledge storage unit, and when the inference attack is detected, the pre-stored probability calculation value corresponding to the probabilistic inference attack logic is output from the inference knowledge storage unit for reference based on the inference attack element check set.
[0033] In the above-mentioned probability inference attack control step, the probability inference attack control unit performs masking or anonymization processing on data attribute information corresponding to an inference attack element to be restricted among the result data, or performs removal processing to remove the data attribute information from the result data, thereby restricting the data attribute information.
[0034] The present invention sets a probability inference attack logic composed of an inference attack element having a probability of inferring sensitive information according to conditions, detects whether an inference attack occurs from result data that is a search result for a query based on the set probability inference attack logic, and restricts data attributes corresponding to inference attack elements that can constitute an inference attack in the result data, thereby having the effect of fundamentally blocking information leakage due to an inference attack.
[0035] In addition, the present invention detects result data that can constitute an inference attack by setting data properties of inferable knowledge data that are determined to be obtainable from other information sources, social engineering, or other methods as inference attack elements and including them in a probability inference attack logic, thereby preventing inference attacks, thereby having the effect of preventing inference of sensitive information using inferable knowledge data.
[0036] In addition, since the present invention configures a probability inference attack logic based on probability, it is possible to perform restriction processing based on probability on at least one of the data attributes corresponding to the inference attack element from the result data, thereby having the effect of more precisely preventing inference of sensitive information so that data attributes having a probability of inferring sensitive information are not used to infer sensitive information.
[0037] In addition, the present invention can preferentially perform restriction processing on at least one of the data attributes with relatively high sensitivity among the data attributes corresponding to the inference attack elements constituting the probability inference attack logic, so that it has the effect of more precisely preventing the inference of sensitive information so that the data attributes with high sensitivity are not used to infer sensitive information.
[0038] In addition, the present invention detects inference attack elements by serializing simultaneous or parallel inference attacks, thereby having the effect of detecting race condition inference attacks and blocking information leakage.
[0039] In addition, the present invention detects inference attacks on result data for queries output from multiple DBMSs, so it has the effect of detecting and defending against inference attacks on multiple DBs.
[0040] Figure 1 is a diagram showing the configuration of a DB inference attack control device based on probability logic according to the present invention.
[0041] FIG. 2 is a diagram showing the configuration of a probability inference control unit of a probability logic-based DB inference attack control device according to the present invention.
[0042] FIG. 3 is a drawing for explaining a method of extracting inference attack elements in an inference attack element extraction unit of a probability inference control unit according to the present invention.
[0043] Figure 4 is a diagram showing the configuration of the inference setting unit of the probability inference control unit according to the present invention.
[0044] Figure 5 is a drawing showing an example of a DB configuration according to one embodiment of the present invention.
[0045] FIG. 6 is a diagram for explaining a method for configuring a probability inference attack logic according to an embodiment of the present invention.
[0046] FIG. 7 is a diagram showing a set of inference attack elements (E) according to one embodiment of the present invention.
[0047] FIG. 8 is a diagram for explaining a method for configuring serial ordering of an inference attack according to concurrent processing of two result data according to one embodiment of the present invention.
[0048] FIG. 9 is a diagram for explaining a method for configuring serial ordering of an inference attack according to parallel processing of two result data according to one embodiment of the present invention.
[0049] FIG. 10 is a diagram for explaining a method for processing data attribute restrictions of result data according to one embodiment of the present invention.
[0050] FIG. 11 is a diagram for explaining a method for processing data attribute restrictions of result data according to another embodiment of the present invention.
[0051] Figure 12 is a flowchart illustrating a DB inference attack control method based on probability logic according to the present invention.
[0052] Referring to the attached drawings below, the configuration and operation of a DB inference attack control device based on probability logic according to the present invention are described in detail, and a DB inference attack control method in the device is described.
[0053] Figure 1 is a diagram showing the configuration of a DB inference attack control device based on probability logic according to the present invention.
[0054] Referring to FIG. 1, the DB inference attack control device based on probability logic of the present invention includes an input / output unit (10), a probability inference control unit (20), and at least one DBMS (30).
[0055] The input / output unit (10) is directly connected to the query terminals of multiple queryers or is connected through a data communication network (1).
[0056] The above query terminal may transmit a query to the probability inference control unit (20) by using various DB client programs such as access through the web using HTTP / HTTPS, a DBMS client program, and a self-developed client program to the input / output unit (10).
[0057] The input / output unit (10) receives a query from the query terminals and provides it to the probability inference control unit (20), and receives a query response to the query from the probability inference control unit (20) and the result data subjected to probability inference control and provides it to the corresponding query terminal.
[0058] The above queryer may be an administrator or any user. Accordingly, the queryer terminal may be an administrator terminal or a user terminal.
[0059] The above query terminal may be a computer terminal such as a desktop computer, personal computer, laptop, etc., or a mobile terminal such as a smartphone or smart pad.
[0060] The above data communication network (1) may be a mobile communication network including 3rd generation (3G), 4G, 5G, etc., a local area network (LAN), a wide area network (WAN), a wired / wireless Internet network including a WiFi network, and a data communication network including an intranet network, an extranet network, etc.
[0061] The interrogator terminal, input / output unit (10), probability inference control unit (20), DBMS (30), and DB (40) may be directly connected by wire depending on various configuration environments, or may be connected via the data communication network (1) using wired / wireless communication.
[0062] The DBMS (30) includes at least one DB (40), and searches the DB (40) for an input query to generate result data for the query, and then transmits the result data to the probability inference control unit (20). The DBMS (30) may be configured to physically exist within the same server as the probability inference control unit (20), may be configured to physically exist in the same space via the above-described data communication network (1), may be configured to be physically separated, such as in a data center or cloud environment, or may be configured in a mixed form thereof. The data configured in the DB (40) may be configured in the form of a single table, or may be configured in the form of multiple tables. In addition, when the data is configured in the form of the multiple tables, the multiple tables may be configured to be located in different DBs (40).
[0063] First, let's define the symbols and terms:
[0064] refers to all inference attack elements included in A.
[0065] is all the inference attack elements included in A (i.e., ) means a set of.
[0066] refers to a function that returns the number of inference attack elements included in A.
[0067] And the above result data (r (u,p,q) ) is defined as in the following mathematical expression 1.
[0068]
[0069] Here, r (u,p,q) DBMS for query of queryer (u) p It means the qth result data, and data d x It is represented as a set of d x is a DBMS for the queryer (u) p The qth result data r (u,p,q) It means data ordered by search order, position order, or time order, etc. included in . For example, y <z이면 데이터 d y is data d z It takes precedence in the order of search, position, or time compared to D u refers to the result dataset for the queryer (u), and r (u,p,q) It consists of a set of Dset. Dset means the result data set for all queryers, and D u It consists of a set of .
[0070] The probability inference control unit (20) provides the input query to the corresponding DBMS (30) and returns result data (r) as a response to the query from each of the DBMSs (30). (u,p,q) ) is entered.
[0071] The probability inference control unit (20) extracts inference attack elements, which are elements that can constitute an inference attack, from among the data attributes included in the input result data.
[0072] When the inference attack element is extracted, the probability inference control unit (20) determines whether the extracted inference attack element constitutes a preset probability inference attack logic.
[0073] If it is determined that a probability inference attack logic is configured, the probability inference control unit (20) restricts data attribute information corresponding to the inference attack element from the result data so that preset sensitive information cannot be inferred, and then provides it to the inquirer terminal of the inquirer through the input / output unit (10).
[0074] The above restriction processing may be masking or anonymizing processing to prevent identification of data attribute information corresponding to the inference attack element, or removal processing to remove the data attribute information from the result data.
[0075] FIG. 2 is a diagram showing the configuration of a probability inference control unit (20) of a probability logic-based DB inference attack control device according to the present invention, FIG. 3 is a diagram for explaining a method of extracting inference attack elements in an inference attack element extraction unit of a probability inference control unit according to the present invention, FIG. 4 is a diagram showing the configuration of an inference setting unit of a probability inference control unit according to the present invention, FIG. 5 is a diagram showing an example of a DB configuration according to an embodiment of the present invention, FIG. 6 is a diagram for explaining a method of configuring a probability inference attack logic according to an embodiment of the present invention, FIG. 7 is a diagram showing an inference attack element according to an embodiment of the present invention, FIG. 8 is a diagram for explaining a method of configuring an inference attack serial ordering according to concurrent processing of two result data according to an embodiment of the present invention, FIG. 9 is a diagram for explaining a method of configuring an inference attack serial ordering according to parallel processing of two result data according to an embodiment of the present invention, and FIG. 10 is a diagram for explaining a method of configuring an inference attack serial ordering according to parallel processing of two result data according to an embodiment of the present invention. This is a drawing for explaining a method for processing data attribute restrictions of result data, and FIG. 11 is a drawing for explaining a method for processing data attribute restrictions of result data according to another embodiment of the present invention.
[0076] Hereinafter, with reference to FIGS. 2 to 11, an example of a DB (40) configured as a table (401) as in FIG. 5 is described, and a method and operation of setting inference attack elements and probability inference attack logic, inference attack detection, and inference control through restriction processing are described.
[0077] First, the configuration of the table configured in DB (40) to be described with reference to one embodiment of the present invention will be described.
[0078] The data in DB (40) may be configured as a single table (401) containing multiple records, each having a different data attribute. In FIG. 5, table (401) is configured with nine records containing nine data attributes. In addition, the data stored in DB (40) may be configured by being divided into multiple tables, each having nine data attributes.
[0079] In the case of Fig. 5, the table (401) is composed of 9 records each having 9 data attributes defined by their respective data attributes (patient name (patient), address (addr), marital status (maritalStatus), sex (sex), age (age), family history (familyHistory), smoking (smoke), helicobacter (helicobacter), cancer (cancer)). The 8 data attributes above, patient, addr, maritalStatus, sex, age, familyHistory, smoke, and helicobacter, may be inference attack factors.
[0080] In the example of Figure 5, the cancer data attribute information is set as sensitive information to be protected. It is assumed that queries directly accessing the cancer data attribute or query results containing its contents are blocked and inaccessible by conventional protection methods such as query language restrictions and access control. Therefore, the queryer cannot directly obtain information about the cancer data attribute from the DB (40).
[0081] The probability inference control unit (20) includes an inference setting unit (110), a plurality of inference attack element extraction units (120) that receive result data from each of a plurality of DBMSs (30), an inference attack ordering configuration unit (130), a probability inference attack detection unit (140), an inference knowledge storage unit (150), a probability inference attack control unit (160), and an inference attack log storage unit (170).
[0082] The inference setting unit (110) includes an inference logic setting interface unit (210), an inference logic generation unit (220), an inference attack element generation unit (230), a sensitive inference attack subset setting unit (240), and a threshold setting unit (250), as shown in FIG. 4.
[0083] The inference logic setting interface unit (210) connects directly to the security manager terminal unit or through the input / output unit (10).
[0084] The inference logic setting interface unit (210) provides an inference logic setting means to a connected security manager terminal, and enables the data properties of tables configured in DBs (40) and data properties corresponding to sensitive information to be checked through the inference logic setting means, and provides a setting means for each inference logic setting element to enable the setting of the corresponding inference logic setting element to be performed.
[0085] The above inference logic setting element includes probability logic and optionally includes inference-capable logic, probability inference attack logic, and a sensitive inference attack subset (s). x ), thresholds, etc.
[0086] The inference logic generation unit (220) includes a probability logic generation unit (221), an inferable logic generation unit (222), and a probability inference attack logic generation unit (223), and then generates a probability inference attack logic, and then stores it in the inference knowledge storage unit (150) through the probability inference attack detection unit (140), or directly in the inference knowledge storage unit (150).
[0087] The probability logic generation unit (221) sets conditions and probabilities for inference attack elements, which are data attributes having a probability of inferring sensitive information provided to the security manager terminal through the inference logic setting interface unit (210), by setting means, and generates a probability model by receiving conditions and probabilities for each inference attack element, and generates probability logic based on the generated probability model.
[0088] When the probability for each inference attack element is set, the probability logic generation unit (221) calculates and sets the probability rules, conditional probability of each variable, etc. in advance, and generates and outputs the probability logic.
[0089] In the example of the above figure 5, the sensitive information is cancer, and among the data attributes, the data attributes directly related to stomach cancer are patient, sex, age, familyHistory, smoke, and helicobacter. Based on this, the probability model is set as shown in Table 1 below.
[0090]
[0091] This means that 4.5% of hospital patients are diagnosed with stomach cancer. Furthermore, being male increases the risk of developing stomach cancer by 7%, being over 60 increases the risk by 10%, having a family history of stomach cancer increases the risk by 12.5%, being a smoker increases the risk by 13%, and being infected with Helicobacter pylori increases the risk by 13%.
[0092] The probability logic and probability calculation corresponding to the probability model shown in Table 1 above are performed as shown in Table 2 below, including logical operations.
[0093] The above logical operations may be entered by the security manager or may be preset. The above logical operations are and(∧), or( ), not(~), >, =, <, etc., and the logical operation expression to be set can be composed of a single logical operation (e.g., A and B, or A ∧ B) or can be applied in a complex manner (e.g., not(A and B), or ~(A ∧ B)).
[0094]
[0095] In the above Table 2, the variable X means a name or ID, and the probability corresponding to the probability logic patient(X) is P(cancer(X)|patient(X)), and the calculated probability value is 0.045 (4.5%). In addition, the probability corresponding to the probability logic (patient(X)∧familyHistory(X)) is P(cancer(X)|patient(X)∧familyHistory(X)), and the calculated probability value is 0.17 (17%). Such probability calculations can be calculated in real time when determining an inference attack, or can be calculated in advance and stored as a set value.
[0096] In addition to the probability logic shown in Table 2 above, the probability logic required for determining an inference attack is as shown in Table 3 below.
[0097]
[0098] In the above Table 3, the variable X represents a name or ID, and the probability corresponding to the probability logic (~patient(X)∧familyHistory(X)) is P(cancer(X) | ~patient(X)∧familyHistory(X)), and the calculated probability value is (0.17 - 0.045) / (1 - 0.045) = 0.1309 (13.09%). In addition, the probability corresponding to the probability logic (~patient(X)∧~familyHistory(X)∧smoke(X)) is P(cancer(X) | ~patient(X)∧~familyHistory(X)∧smoke(X)), and the calculated probability value is (0.30 - 0.17) / (1 - 0.17) = 0.1566 (15.66%). Probability calculations like this can be calculated in real time when determining an inference attack, or they can be calculated in advance and stored as a set value.
[0099] The probability logic generation unit (221) must construct probability logic with data attributes having the above-described probabilities, but among the data attributes such as patient, sex, age, familyHistory, smoke, and helicobacter, which are inference attack elements, sex has a probability of inferring sensitive information only when the corresponding data attribute information is male, so the inference attack element is changed to male, and age has a probability of inferring sensitive information only when the data attribute information is 60 years or older, so the inference attack element is changed to morethan60 (60 years or older) to construct probability logic. That is, the probability logic generation unit (221) generates inference attack elements, patient (U), male (V), morethan60 (W), familyHistory (X), smoke (Y), and helicobacter (Z), from probability logic having conditions and probability values that can infer sensitive information, and outputs them to the probability inference attack logic generation unit (223).
[0100] In addition, the probability logic generation unit (221) generates a probability calculation value for the probability logic and stores it in the inference knowledge storage unit (150).
[0101] The probability inference attack logic generation unit (223) receives data attributes that can directly infer the sensitive information among data attributes excluding data attributes corresponding to the sensitive information configured in the DBs (40) and logical operations by means of a setting means for the probability inference attack logic setting element provided to the security manager terminal through the inference logic setting interface unit (210), and receives probability logic from the probability logic generation unit (221) to generate the probability inference attack logic.
[0102] The above probability inference attack logic can be defined as in the following mathematical expression 2, and an example configuration is explained with reference to 501 of FIG. 6.
[0103]
[0104] Here, α x is a probability inference attack logic, and A is a probability inference attack logic (α x ) is a set of.
[0105] Probability inference attack logic (α) x ) includes one or more data attributes and one or more probability models, and includes probability logic generated based on the data attributes and the probability models.
[0106] 501 in Fig. 6 is a probability inference attack logic (α) that includes only probability logic in the DB configuration example of Fig. 5. x ) is shown.
[0107] 501 in Figure 6 represents an inference attack element consisting of patient name, sex, age, family history, smoke, and helicobacter, which are data attributes that can directly infer the name of a patient with cancer when the name of a patient with cancer is considered sensitive information.
[0108] In addition, 501 of the above Fig. 6 represents a probability inference attack logic in which the probability logic input from the probability logic generation unit (221) is applied, and male is applied as an inference attack element instead of sex, and morethan60 is applied as an inference attack element instead of age. That is, in the case of 501 of Fig. 6, the probability inference attack logic (α) w , α x ) can be expressed as in the following mathematical formula 3.
[0109]
[0110] Here, α w is the previous probability inference attack logic, and α x is α w This refers to the following probability inference attack logic.
[0111] To explain again, the probability inference attack logic of the above mathematical expression 3, α w This means that patient U, who is a man over 60 years old, has a family history of cancer, smokes, and has Helicobacter pylori in his stomach, is a deductive attack that can be used to infer that he has stomach cancer.
[0112] The probability inference attack logic generation unit (223) generates the above probability inference attack logic α w It is created and stored in the inference knowledge storage unit (150) as one of the inference knowledge.
[0113] Here, we assume that controls are added to prevent the acquisition of information about the data attribute, patient, which is the identifying information. Therefore, the probability inference attack logic α of the above mathematical expression 3, which does not include the controlled data attribute, patient, is x It can be generated and stored in the inference knowledge storage unit (150) as one of the inference knowledge. In this way, since the data attribute and patient are controlled, the probability inference attack logic α w Wow α xThe valid inference attack factors included in are male, morethan60, family history, smoke, helicobacter, and the same five data attributes, so the following explanation uses the probability inference attack logic α. x It is explained based on .
[0114] Since the queryer cannot directly obtain information about the data attributes of Figure 5, patient and cancer, the probability inference attack logic, α x It is not possible to accurately infer whether a specific patient has cancer. In other words, it is not possible to determine whether a specific person has cancer based only on information such as male, age over 60, family history, smoke, and Helicobacter.
[0115] For example, in Figure 5, records 1, 3, 6, and 8 in table (401) are cases where patients with stomach cancer are identified, and the information acquirer uses a probability inference attack logic (α) x ) If the information on male (male(V)), over 60 years old (morethan60(W)), family history (familyHistory(X)), smoking (smoke(Y)), and Helicobacter (helicobacter(Z)) that constitute the inference attack elements is obtained, the person obtaining the information can infer that there is a patient with gastric cancer, but since the patient name (patient) data attribute is restricted as sensitive information, the name of the patient with gastric cancer cannot be found out.
[0116] Therefore, the information obtainer uses the above probability inference attack logic (α) to accurately infer the cancer patient. x ) will try to infer that the patient has cancer by finding other inference attack factors that are not included in the original text.
[0117] For example, if you know or obtain this information from another source that a 65-year-old woman named Mary lives in Los Angeles and is single, the above probability inference attack logic (α) x ) by additionally obtaining address (addr) and marital status (maritalStatus) information, it is possible to infer that record 1 in Figure 5 corresponds to Mary's information. In other words, it is possible to infer that Mary is a patient with stomach cancer.
[0118] At this time, it can be inferred that record 1 in Figure 5 is Mary's information based on the sex and age information, but record 2 in Figure 5 also has the same sex and age as Mary in record 1, so in order to infer which of Mary and Jane has stomach cancer, address (addr) and marital status (maritalStatus) information will be required as described above.
[0119] As another example, if we know, or have obtained from another source, that a 70-year-old man named Brandon lives in San Diego and is married, adding his address (addr) and marital status (maritalStatus) information would identify record 8 in Figure 5 as Brandon's information. Therefore, we can infer that Brandon has stomach cancer.
[0120] Therefore, the inferable logic generation unit (222) receives one or more data attributes that are judged to be usable to increase the accuracy of inference attacks on sensitive information of the DB (40) from the security manager terminal through the inferable logic setting interface unit (210) and generates the inferable logic (c x ) is generated. The above inferable logic can be defined as in the following mathematical expression 4, and a configuration example is described with reference to 502 of FIG. 6.
[0121]
[0122] Here, c x is an inferable logic that is judged to be usable to increase the accuracy of inference attacks on sensitive information, and C represents a set of inferable logic.
[0123] 502 in Fig. 6 is the inferable logic (c) in the DB configuration example of Fig. 5. x ) is shown, and when the name of a patient with cancer is considered as sensitive information, it shows the inferable logic consisting of the address (addr(A)) and maritalStatus (maritalStatus(B)), which are data attributes that can be used to infer the name of a patient with cancer. That is, in the case of 502 in Fig. 6, the inferable logic (c x ) can be expressed as in the following mathematical expression 5.
[0124]
[0125] Here, A represents address and B represents marital status information.
[0126] Therefore, when the above-mentioned inferable logic generation unit (222) generates the inferable logic, the inferable logic (c) x ) is output to the probability inference attack logic generation unit (223).
[0127] The probability inference attack logic generation unit (223) receives the probability logic input from the probability logic generation unit (221) and the inferable logic input from the inferable logic generation unit (222), and generates and outputs the probability inference attack logic including the probability logic and the inferable logic. That is, the probability inference attack logic generation unit (223) generates the probability inference attack logic, α, which includes only the probability logic, as in 501 of the above-described FIG. 6. w Wow α x The probability inference attack logic, which is an extended inference attack logic such as 503 of FIG. 6 and the following mathematical expression 6, is applied to the inference logic. w Wow α x is generated and stored in the inference knowledge storage unit (150).
[0128]
[0129] The inference attack element generation unit (230) generates the probability inference attack logic (α) generated from the inference logic generation unit (220). x ) and inferable logic (c x ) is input, and the data properties configured in the probability inference attack logic are set as inference attack elements as shown in Fig. 6.
[0130] The above-described inference attack element generation unit (230) provides the inference attack element set (E), which is information on the set inference attack elements, to the inference attack element extraction units (120). According to an embodiment, the inference attack element set (E) may be provided to the security manager terminal unit through the inference logic setting interface unit (210). The inference attack element set (E) may be expressed as in the following mathematical expression 7.
[0131]
[0132] Here e i is an inference attack element, and E represents a set of inference attack elements.
[0133] For example, in Figure 7, e1=patient, e2=addr, e3=maritalStatus, e i =morethan60, e j =male, e k =familyHistory, e l =smoke, e m =It could be helicobacter.
[0134] The sensitive inference attack subset setting unit (240) is a sensitive inference attack subset (s) composed of one or more inference attack elements that have a more sensitive effect than other inference attack elements in inferring sensitive information based on probability logic among the inference attack elements. x ) is set. The above sensitive inference attack subset (s) x) may be family history, helicobacter, etc. in the table (401) of Fig. 5.
[0135] The threshold setting unit (250) provides a threshold setting means to the security manager terminal, and through the threshold setting means, sets the risk judgment threshold (λ) and the sensitive inference attack element threshold (ρ). x ), the inference logic threshold (τ) is input and set.
[0136] The above risk judgment threshold (λ) is a threshold that determines whether an inference attack is successful or not for the inference attack elements extracted from the result data input from the DBMS (30), and is set as a real number between 0 and 1, i.e., a probability value. The above risk judgment threshold (λ) may be set to 0.5 (50%) according to one embodiment, and the probability inference attack logic (α) x ) is applied to detect and control inference attack factors so that the probability calculated based on it does not exceed 50%.
[0137] The above risk judgment threshold can be defined as in the following mathematical expression 8.
[0138]
[0139] The above sensitive inference attack element is an inference attack element that has a more sensitive effect than other elements in inferring cancer, which is set as sensitive information based on probability logic, among the inference attack elements, and the subset composed of these sensitive inference attack elements is called the sensitive inference attack subset (s). x ) is called.
[0140] Among the attack inference elements in Fig. 7, the sensitive inference attack element is family history (e k ) and Helicobacter (e m ) is set to sensitive inference attack elements and sensitive inference attack subset (s x ) and sensitive inference attack factor threshold (ρ x) is defined as shown in Table 4 below, and the sensitive inference attack element threshold (ρ) x ) can be expressed as in the following mathematical expression 9.
[0141]
[0142]
[0143] Here, len(s x ) is a sensitive inference attack subset (s) x ) returns the number of elements.
[0144] That is, the threshold value of the sensitive inference attack factor (ρ) x ) is a sensitive inference attack subset (s) x ) is set to an integer value greater than or equal to the number of elements.
[0145] Sensitive inference attack factor threshold (ρ) x ) is a sensitive inference attack subset (s) x ) is determined to have occurred, the sensitive inference attack subset (s) x ) is used to control the success of inference attacks by restricting the disclosure of information on the number of inference attack elements corresponding to the threshold among the inference attack elements that constitute the above.
[0146] For example, the sensitive inference attack factor threshold (ρ) x ) is set to 1, and the inference attack subset is s x = {e k , e m}={familyHistory, helicobacter}, len(s x )=2, so the two elements that make up the inference attack subset are the inference attack elements, e k , e m Controls the success of inference attacks by restricting the disclosure of information corresponding to one of the items.
[0147] The above inference attack element threshold (ρ) x) are selected from the earliest or latest order based on the input time and then restricted, or are selected randomly and then restricted.
[0148] In addition, the threshold setting unit (250) receives from the security manager an inference-capable logic threshold (τ) for inference attack elements to be limitedly processed among the inference attack elements extracted from the result data input from the DBMS (30) and stores it in the inference knowledge storage unit (150) to set it.
[0149] The inferable logic threshold (τ) is defined as in the following mathematical expression (10).
[0150]
[0151] Here, c x means inferable logic, and len(c x ) returns the number of elements in the inferable logic.
[0152] As shown in the above mathematical expression 10, the inferable logic threshold (τ) is a subset of the inferable logic (c x ) is set to an integer value greater than or equal to 0 and less than or equal to the number of elements of the logic. Therefore, if the inferable logic threshold (τ) is set to 0, the inferable logic (c x ) are not subject to restriction processing.
[0153] The inferable logic threshold (τ) is used to restrict information on inferable attack elements corresponding to the inferable logic threshold (τ) among the inferable attack elements constituting the inferable logic from being disclosed when it is determined that inferable attack elements constituting the inferable logic are included among the inferable attack elements extracted from the result data. The inferable attack elements corresponding to the inferable logic threshold (τ) are restricted by selecting them in the earliest order based on the input time, selecting them in the latest order, or selecting them randomly.
[0154] As described above, the risk judgment threshold (λ) must be set, and the sensitive inference attack element threshold (ρ) must be set. x ) and the inferable logic threshold (τ) may not be set, or only one of them may be set, or the sensitive inference attack element threshold (ρ) may be set. x ) and the inferable logic threshold (τ) may be set in combination. Therefore, by applying restriction processing by appropriately setting the above three types of thresholds in combination, it is possible to prevent sensitive information from being leaked through inference attacks while also improving data usability.
[0155] The security manager can access the inference logic setting interface (210) via the security manager terminal to add, delete, and change the above-described probability models, probability logic, the above-described probability inference attack logic, and inference-capable logic, and can also add, delete, and change thresholds. In addition, the security manager can change the values of each threshold.
[0156] The inference attack element extraction unit (120) receives and sets the inference attack element set (E) from the inference setting unit (110) as shown in Fig. 3, and sets the result data (r), which is the search result data for a query from an arbitrary queryer, from the DBMS (30). (u,p,q) ) is input, and data attribute information corresponding to the inference attack elements of the inference attack element set is extracted from the input result data, and then an inference attack transaction (t) is created to include the inference attack elements corresponding to the extracted data attributes. (u,p,q) ) is generated and output to the inference attack sequence configuration unit (130). The inference attack transaction is defined as in the following mathematical expression 11.
[0157]
[0158] Here, t (u,p,q) is a DBMS by an arbitrary queryer u p It means the qth inference attack transaction, and the inference attack element φ xIt consists of a set of φ x is the qth inference attack transaction (t) of DBMSp by an arbitrary queryer u. (u,p,q) ) is included in the set of inference attack elements (E). That is, any φ x is any e i (e i ∈E) and is mapped to the inference attack element (φ x ) is an inference attack element ordered by lookup order, position order, or time order. That is, for times y and z, y <z이면 추론공격요소 φ y is an inference attack element φ z Tset is the set of inference attack transactions attempted by all queryers, and all T u It consists of a set of T u refers to the transaction set of an inference attack by an arbitrary queryer u, and t (u,p,q) It consists of a set of .
[0159] The inference attack transaction in which the extracted inference attack elements are serially ordered can be defined as in the following mathematical expression 12.
[0160]
[0161] Here, refers to a serially ordered inference attack transaction, and DBMS by an arbitrary queryer u p The qth inference attack transaction set (Tu={t (u,p,q)}) is included. And Is It means a serially ordered set of inference attack transactions. Therefore, for time y and z, y <z이면 추론공격 트랜잭션 is a speculation attack transaction Takes precedence over
[0162] Figure 8 is the same DBMS p1 The first result data (r) for the queryers a and b input to the inference attack element extraction unit (120)(a,p1,q1) ) and the second result data (r (b,p1,q2) ) shows a case where the inference attack elements occur simultaneously and are input, and Fig. 9 shows a case where they occur in parallel and are input. This will be explained in more detail with reference to Figs. 8 and 9.
[0163] In the case of Fig. 8, the inference attack element extraction unit (120) extracts the inference attack element e from the first result data for the queryer a. m and e k Extract the inference attack element e m Time(clock(e) m ) is Δ3, and the inference attack factor e k Time(clock(e) k )) is Δ6. Since Δ3<Δ6, the inference attack element extraction unit (120) extracts the inference attack element e m This e k Inference attack transaction t is ordered to take precedence over (a,p1,q1) ={φ1=e m , φ2=e k}= It consists of.
[0164] The inference attack element extraction unit (120) extracts the inference attack element e from the second result data for the queryer b. k and e m Extract the inference attack element e k Time(clock(e) k ) is Δ4, and the inference attack factor e m Time(clock(e) m )) is Δ5. Since Δ4<Δ5, the inference attack element extraction unit (120) extracts the inference attack element e k This e m Inference attack transaction t is ordered to take precedence over (b,p1,q2) ={φ1=e k , φ2=e m}= It is configured and output to the inference attack sequence configuration unit (130).
[0165] Here, the start time of the first result data (clock(r) (a,p1,q1) )) is Δ2, and the start time of the second result data (clock(r (b,p1,q2) )) is Δ1, and Δ1< Δ2.
[0166] Therefore, the inference attack sequence configuration unit (130) is an inference attack transaction t (b,p1,q2) ={φ1=e k , φ2=e m}= , inference attack transaction t (a,p1,q1) ={φ1=e m , φ2=e k}= It is output in order. That is, this Takes precedence over
[0167] In the case of Figure 9, the second result data was input faster than the first result data, so the inference attack transaction t is the same as Figure 9. (b,p1,q2) ={φ1=e k , φ2=e m}= , inference attack transaction t (a,p1,q1) ={φ1=e m , φ2=e k}= It is output in order.
[0168] The inference attack sequence configuration unit (130) serializes the inference attack transactions output from all inference attack element extraction units (120) using the above-described method and outputs them to the probability inference attack detection unit (140).
[0169] The mapping between the above result data and the corresponding inference attack transaction can be defined as in the following mathematical expression 13.
[0170]
[0171] Here, r i,j is the result data record, r i is m result data records (r i,j) is the result data, R is n result data records (r i ) each refers to a result data set consisting of . And, means the inference attack transaction record, and according to the above mathematical expression 12, is a set of m inference attack transaction records ( ) is a serially ordered inference attack transaction, is a set of n serially ordered inference attack transactions ( ) each refers to a serially ordered set of inference attack transactions.
[0172] And, inference attack transaction is the result data r i It is defined as being mapped to and is a speculation attack transaction. A set of inference attack elements is the result data r i A set of inference attack elements {[r i ]} are the same. Therefore, the inference attack transaction record is the result data record r i,j and is mapped to a transaction record for inference attack. A set of inference attack elements is the result data record {[r i,j ]} are the same as each other.
[0173] The probability inference attack detection unit (140) configures an inference attack element check set, which is a set of inference attack elements that includes inference attack elements provided to the query terminal stored in the inference knowledge storage unit (150) in the inference attack elements included in the inference attack transaction from the inference attack ordering configuration unit (130).
[0174] The above probability inference attack detection unit (140) detects a sensitive inference attack subset (s) based on the inference attack element check set. x ) and sensitive inference attack factor threshold (ρ x ) determines the inference attack elements to be processed.
[0175] The above sensitive inference attack subset (s)x ) and sensitive inference attack factor threshold (ρ x ) is performed as in the following mathematical expression 14.
[0176]
[0177]
[0178] Here, the input parameters are the set of pre-provided inference attack elements and the inference attack element check set △ containing the inference attack transactions, and the sensitive inference attack subset s. x , sensitive inference attack factor threshold ρ x and a set of sensitive inference attack elements that have been subject to prior processing am.
[0179] And, after inputting the above parameters, the sensitive inference attack subset s is selected from the inference attack element check set △. x A set of inference attack elements corresponding to Produce (line 1), and the above-mentioned set of inference attack factors produced If this is not an empty set (i.e., the sensitive inference attack subset s in the inference attack element check set △) x If this is configured, the above set of inference attack elements produced The above set of sensitive inference attack elements that have been limited in A set of inference attack factors θ is calculated by removing (second line), and the calculated set of inference attack factors If this is an empty set (i.e., a sensitive inference attack subset s in the inference attack element check set △) x If this is not configured), the above-mentioned set of inference attack elements θ is set to an empty set (line 3), and the number k of inference attack elements to be determined for new restriction processing is determined from the above-mentioned set of inference attack elements θ (line 4), and if the value k in the above-mentioned set of inference attack elements θ is positive, the set of k selected inference attack elements ( ) is produced (line 5), otherwise a set of inference attack factors ( ) is set to an empty set (line 6).
[0180] In addition to the sensitive inference attack elements that are determined to be restricted based on the above mathematical expression 14, the determination of the inference attack elements to be restricted for each inference attack transaction record is performed as in the following mathematical expression 15.
[0181]
[0182] Here, the input parameter is a set of sensitive inference attack elements to be restricted in the inference attack transaction record that constitutes the inference attack transaction. Check set ω of inference attack elements that have been removed, and probability inference attack logic α x , a set of sensitive inference attack elements that are subject to limited processing for the above inference attack transaction records. and the risk judgment threshold λ.
[0183] And, after inputting the above parameters, the set δ, which means the newly restricted processing determined inference attack elements for the inference attack transaction record, is initialized to an empty set (line 1), and the inference attack element check set ω and the probability inference attack logic α x Common inference attack elements in (ω∩{[α x ]}) from the above sensitive inference attack element set to be restricted Determine the target set of inference attack factors by removing (2nd line) and, based on the above inference attack element check set ω, the above probability inference attack logic α x The risk probability p is calculated (line 4), and it is determined whether the calculated risk probability p exceeds the risk judgment threshold λ (line 5). Then, if the risk probability p exceeds the risk judgment threshold λ, the target set of the inference attack element is determined. In the 6th line, one inference attack element ε to be newly restricted is calculated, and the set of inference attack elements δ for which restriction processing has been decided is updated by adding the inference attack element ε for which restriction processing has been decided (7th line), and the inference attack element check set ω and the inference attack element determination target set In the above, the inference attack element ε determined by the above limitation processing is removed and updated (lines 8 to 9). Then, lines 4 to 10 are repeatedly performed based on the updated inference attack element check set ω, but if the risk probability p calculated based on the updated inference attack element check set ω does not exceed the risk judgment threshold λ, the repetition is terminated (line 12).
[0184] Based on the above mathematical expressions 14 and 15, the determination of the inference attack element to be restricted for each inference attack transaction record that constitutes the inference attack transaction and the restriction processing accordingly are performed as in the following mathematical expression 16.
[0185]
[0186]
[0187] In the above mathematical expression 16, all inference attack transactions For (line 1), execution is performed from line 2 to line 21. First, the above inference attack transaction Initialize the set of inference attack elements μ to be restricted for processing (line 2), and the inference attack transaction A set of inference attack elements The inference attack element check set △ is calculated including the previously provided inference attack element set Γ (3rd line), and the sensitive inference attack subset s is calculated from the previously restricted inference attack element set Ψ. x A set of sensitive inference attack elements corresponding to the limited processing (Line 4) and the probability inference attack logic α. x The above set of sensitive inference attack elements that have been processed in response to The number of inference attack elements is the sensitive inference attack element threshold ρ x If it is smaller than (line 5), the set of sensitive inference attack elements that are decided to be newly restricted using the above mathematical expression 14 is (Line 6) and the above-mentioned set of sensitive inference attack elements that have been subject to restriction processing The above set of sensitive inference attack elements that have been decided to be newly restricted A set of sensitive inference attack elements that can be combined and processed Produces (line 7). Probability inference attack logic α x The above set of sensitive inference attack elements that have been processed in response to The number of inference attack elements is the sensitive inference attack element threshold ρ x If not smaller than the above, the set of sensitive inference attack elements subject to the above limitation A set of sensitive inference attack elements to be processed (Line 9)
[0188] And, inference attack transaction Each inference attack transaction record that constitutes To determine the inference attack elements to be limited, lines 10 to 15 are performed. That is, first, the inference attack transaction record A set of inference attack factors that can be limited to Initialize to an empty set (line 11), and inference attack transaction record A set of inference attack elements The above sensitive inference attack element set to be restricted in a state including the provided inference attack element set Γ By removing the inference attack element check set ω, the above sensitive inference attack subset (s) is generated (line 12). x ) and critical value (ρ x ) based on the above-mentioned probability inference attack logic α, which excludes the inference attack elements determined by the restriction processing, and checks the above-mentioned probability inference attack elements check set ω. xBy calculating the risk probability p (line 13), if the calculated risk probability p exceeds the risk judgment threshold λ, the set of inference attack elements δ that is determined to be newly restricted is calculated by referring to the above mathematical expression 15 (line 14), and if the calculated risk probability p does not exceed the risk judgment threshold λ, the set of inference attack elements δ that is determined to be newly restricted is set to an empty set (line 15), and the set of inference attack elements μ that is to be restricted is calculated j A set of sensitive inference attack elements that can be processed in a limited manner The set of inference attack elements δ that have been decided to be processed with new restrictions is updated by adding them (line 16).
[0189] And, the above inference attack transaction All inference attack element transaction records included in A set of inference attack factors μ that can be restricted for processing j Once the calculation is completed, the above inference attack transaction A set of inference attack factors that can be limited to (Line 18) and a set of sensitive inference attack elements to be restricted from the above inference attack element check set △ The inference attack elements that have been removed are updated by adding them to the previously provided inference attack element set Γ (line 19), and the set of sensitive inference attack elements to be restricted is processed in the previously restricted inference attack element set Ψ. Update by combining (line 20), and the above set of inference attack elements to be limited The above inference attack transaction The result data r mapped to i The result data after limiting processing and generate (line 21), and the above-mentioned result data is restricted Provides the query terminal (line 22).
[0190] Here, by the above mathematical expression 13, the set of inference attack elements to be processed is limited. The above inference attack transaction The result data r mapped to i The result data is limited by limiting processing. Generating means that each inference attack element that is to be processed is restricted. Each inference attack transaction record by Result data record r mapped to i,j The result data record is restricted by restricting processing. This means that they are created and match each other.
[0191] As explained above, the probability inference attack detection unit (140) first checks the inference attack element set and adds a sensitive inference attack subset (s). x ) is composed (lines 1 and 2 of Equation 14), and the sensitive inference attack subset (s x ) is configured, the threshold information of the inference knowledge is the sensitive inference attack element threshold (ρ) x ) determines the inference attack elements to be restricted (lines 2, 4-5 of mathematical expression 14).
[0192] The probability inference attack detection unit (140) is a probability inference attack logic (α) x ), inferable logic (c x ), sensitive inference attack subset (s) x ) and threshold information, and loads the inference knowledge, and inputs the inference attack transaction (130) from the inference attack ordering component based on the loaded inference knowledge. ) contained in each inference attack transaction record ( ) in the inference attack elements, the threshold value (ρ) of the above sensitive inference attack elements x ) based on the set of inference attack elements to be checked, excluding the inference attack elements to be restricted, and the probability inference attack logic (α) x ) is calculated to infer the risk probability for sensitive information (lines 12-13 of Equation 16), and it is determined whether the calculated risk probability exceeds the preset risk judgment threshold (λ) (line 14 of Equation 15).
[0193] If the above risk probability exceeds the preset risk judgment threshold (λ), the probability inference attack detection unit (140) detects an inference attack transaction ( ) constitutes each inference attack transaction record ( ) based on the inference attack element check set including the inference attack element of each inference attack transaction record ( ) among the inference attack elements, a subset of sensitive inference attacks (s) x ) and inferable logic (c x ) sets the inference attack elements to be limited among the inference attack elements excluding the inference attack elements of (lines 12 to 14 and 16 of mathematical expression 16 and mathematical expression 15).
[0194] In addition, the probability inference attack detection unit (140) detects the inference possible logic (c) based on the above inference attack element check set. x ) is configured, and when the inferable logic is configured, the inferable attack elements to be limited by the inferable logic threshold (τ) among the inferable attack elements of the inferable logic are determined.
[0195] At this time, the probability inference attack detection unit (140) refers to the previously limited inference attack elements stored in the inference knowledge storage unit (150) (line 4 of mathematical expression 16) and sets the sensitive inference attack element threshold (ρ). x ) among the inference attack elements corresponding to the current inference attack transaction, the previously restricted inference attack elements are included as inference attack elements to be restricted in the result data corresponding to the current inference attack transaction (lines 5 to 7 of mathematical expression 16).
[0196] In other words, the probability inference attack detection unit (140) sets three thresholds for the above limitation processing in a complex manner, and when determining whether each threshold is exceeded, the sensitive inference attack threshold (ρ) is set. x ) to be prioritized for limiting the inference attack elements with relatively high sensitivity (lines 4 to 7 of Equation 16), and then the sensitive inference attack threshold (ρ) is determined. x) based on the check set of inference attack elements excluding the inference attack elements determined by the restriction processing, the above probability inference attack logic (α) x ) is calculated (lines 12 to 13 of Equation 16), and if the calculated risk probability exceeds the risk judgment threshold (λ), an inference attack element to be restricted is additionally determined (lines 14 and 16 of Equation 16), and lastly, it is desirable to determine an inference attack element to be restricted by the inference logic threshold (τ) depending on whether an inference logic is configured.
[0197] Here, the above sensitive inference attack threshold (ρ x ) is stored in the inference knowledge storage unit (150) as an inference attack element that has been previously limited as inference knowledge (line 20 of mathematical expression 16). In addition, the inference attack element that has been previously limited as inference knowledge is stored in the inference knowledge storage unit (150) as an inference attack element that has been previously limited as inference knowledge as inference attack element.
[0198] However, the above sensitive inference attack threshold (ρ x ) is determined to be restricted based on the inference attack element check set (ω in the 12th line of Equation 16) excluding the inference attack element determined to be restricted based on the inference attack element check set (δ in the 14th line of Equation 16), each result data record (r i,j ) is applied to perform restriction processing (lines 16 to 18 and 21 of Equation 16), and the next result data record (r i,j+1 ) does not affect the restriction processing (lines 11 and 16 of Equation 16), and also the following result data (r i+1 ) so as not to affect the restriction processing for the reasoning attack element that has been restricted (i.e., not including δ in the 20th line of mathematical expression 16), thereby storing it in the reasoning knowledge storage unit (150) so as not to be included in the reasoning attack element that has been restricted (i.e., not including δ in the 20th line of mathematical expression 16), the effect of increasing data usability can be obtained.
[0199] When the inference attack elements to be restricted are determined, the probability inference attack detection unit (140) outputs restriction processing request information including information on the inference attack elements to be restricted to the probability inference attack control unit (160).
[0200] The probability inference attack control unit (160) receives information on inference attack elements to be restricted for arbitrary result data from the probability inference attack detection unit (140), restricts the inference attack elements to be restricted for the result data corresponding to the result data input from the DBMS (30), and outputs the information through the input / output unit (10).
[0201] About the DB in Fig. 5<familyHistory, smoke, helicobacter, sex, age, maritalStatus, addr> Assuming that a query like this is searched, the risk judgment threshold (λ) is 0.5, and the sensitive inference attack subset (s x ), s x ={e k , e m}={familyHistory, helicobacter}, and the threshold of the sensitive inference attack factor (ρ x ) is 1, and the inferable logic threshold (τ) is set to 1.
[0202] The above query<familyHistory, smoke, helicobacter, sex, age, maritalStatus, addr> The result data searched and restricted by is as shown in Table 5 below. Here, the symbol * indicates masked or private information.
[0203]
[0204] For example, in the case of record 1 of Fig. 5, the probability inference attack detection unit (140) checks the inference attack element check set for the result data and adds a sensitive inference attack subset (s x) is determined to exist. At this time, the inference attack elements that constitute record 1 are included in the inference attack element check set, so the sensitive inference attack subset (s) defined in the example of Table 4 above is x = {e k ,e m} ={familyHistory, helicobacter}) is judged to exist, and the sensitive inference attack element threshold (ρ) x ) is 1, the probability inference attack detection unit (140) detects the sensitive inference attack subset (s x = {familyHistory, helicobacter}) is shown as an example in which one of the sensitive inference attack elements is decided to be restricted. The restricted sensitive inference attack element, helicobacter, is stored in the inference knowledge storage unit (150) as a previously restricted sensitive inference attack element. The inference attack element check set includes not only the inference attack elements of the query but also the inference attack elements provided by the previous query.
[0205] Next, the probability inference attack detection unit (140) calculates the risk probability for record 1 of FIG. 5 using the probability logic of Table 2 and the conditional probability table by data attribute of Table 3. In the case of record 1 of FIG. 5, the risk probability can be expressed as in Equation 17 below. Here, Equation 17 is the sensitive inference attack element threshold (ρ x =1) means that the calculation is performed excluding helicobacter, which is an inference attack factor restricted by the limit processing. Record 1 in Table 5 shows an example of restricting helicobacter.
[0206]
[0207] Referring to Table 2 above, P(cancer(X)|patient(X)∧familyHistory(X)∧smoke(X)∧helicobacter(X)∧morethan60(X))=0.53, and referring to Table 3, P(cancer(X)|~patient(X)∧~familyHistory(X)∧~smoke(X)∧helicobacter(X))=0.1857, so the risk probability is calculated as ((0.53)-(0.1857)) / (1-0.1857)= 0.4228 (i.e., 42.28%).
[0208] Therefore, since the calculated risk probability does not exceed 50%, which is the risk judgment threshold (λ) value, the probability inference attack detection unit (140) does not additionally determine the inference attack elements to be restricted according to the risk probability.
[0209] In addition, the probability inference attack detection unit (140) includes an inference-capable logic (c) in the inference attack element check set. x ={maritalStatus, addr}) is configured. As a result of the determination, since an inferential logic is configured, the probability inference attack detection unit (140) determines one of the inferential attack elements, maritalStatus (marital status) and addr (address), which constitute the inferential logic, as the inferential attack element to be restricted, as the inferential attack element to be restricted, as the inferential logic threshold (τ) is set to 1. Record 1 in Table 5 shows an example of restricting addr (address).
[0210] As another example, taking the case of record 6 of FIG. 5 as an example, the probability inference attack detection unit (140) detects a sensitive inference attack subset (s) of inference attack elements included in the result data. x = {familyHistory, helicobacter}) contains all the sensitive inference attack elements, so the sensitive inference attack element threshold (ρ) x) is set to 1, one of the sensitive inference attack elements is determined as an inference attack element to be restricted. At this time, by referring to the previously restricted inference attack elements stored in the inference knowledge storage unit (150), helicobacter, which is a sensitive inference attack element that has been restricted, is determined as an inference attack element to be restricted. Record 6 of Table 5 shows an example of restricting helicobacter.
[0211] In addition, the probability inference attack detection unit (140) calculates the risk probability for record 6 of FIG. 5 as in the following mathematical expression 18, and determines whether the risk probability exceeds the risk judgment threshold (50%). Here, the risk probability is the sensitive inference attack element threshold (ρ x =1) means that the calculation is made excluding helicobacter, which is an inferred attack factor determined by restriction processing.
[0212]
[0213] That is, referring to Table 2 above, P(cancer(X)|patient(X)∧familyHistory(X)∧smoke(X)∧helicobacter(X)∧morethan60(X)∧male(X))=0.6, and referring to Table 3 above, P(cancer(X)|~patient(X)∧~familyHistory(X)∧~smoke(X)∧helicobacter(X))=0.1857, so the risk probability of record 6 in Fig. 5 is calculated as ((0.6)-(0.1857)) / (1-0.1857)= 0.5088 (i.e., 50.88%).
[0214] Therefore, since the calculated risk probability exceeds the risk judgment threshold of 50%, the probability inference attack detection unit (140) determines one of male and morethan60 (60 years or older) as the inference attack factor to be restricted, excluding the sensitive inference attack factor and the inferable logic inference attack factor. Record 6 in Table 5 shows an example in which morethan60 was determined as the inference attack factor to be restricted.
[0215] The probability inference attack detection unit (140) then recalculates the risk probability for record 6 as shown in Equation 19 below and determines whether the risk probability exceeds the risk judgment threshold (50%). Therefore, this means that the risk probability is calculated by additionally excluding morethan60 from a state that already reflects the inference attack factor, helicobacter, which has been determined to be subject to restricted processing.
[0216]
[0217] Referring to Table 3 above, since P(cancer(X)|~patient(X)∧~familyHistory(X)∧~smoke(X)∧~helicobacter(X)∧morethan60(X))=0.1754, the risk probability is ((0.5088)-(0.1754)) / (1-0.1754)=0.4043(40.43%), which does not exceed the risk judgment threshold of 50%, and therefore the probability inference attack detection unit (140) does not additionally determine the inference attack elements to be restricted according to the risk probability.
[0218] In addition, since the inferable logic threshold (τ) of the probability inference attack detection unit (140) is set to 1, it determines one addr among the inferable logic elements, maritalStatus and addr, as an inferential attack element to be restricted, as determined in the example of record 1. Record 6 of Table 5 also shows an example of restricting addr (address).
[0219] As another example, taking the case of record 8 of FIG. 5 as an example, the probability inference attack detection unit (140) detects that all the sensitive inference attack elements of the sensitive inference attack subset (sx = {familyHistory, helicobacter}) are included in the result data, so the sensitive inference attack element threshold (ρ) x) is set to 1, one of the sensitive inference attack elements is determined as an inference attack element to be restricted. At this time, by referring to the previously restricted inference attack elements stored in the inference knowledge storage unit (150), helicobacter, which is a sensitive inference attack element that has been restricted, is determined as an inference attack element to be restricted. Record 8 in Table 5 also shows an example of restricting helicobacter.
[0220] In addition, the probability inference attack detection unit (140) calculates the risk probability for record 8 of FIG. 5 using the above mathematical expression 18 and determines whether the risk probability exceeds the risk judgment threshold (50%). Here, the risk probability is the sensitive inference attack element threshold (ρ x =1) means that the calculation is made excluding helicobacter, which is an inferred attack factor determined by restriction processing.
[0221] Therefore, referring to Table 2 above, P(cancer(X)|patient(X)∧familyHistory(X)∧smoke(X)∧helicobacter(X)∧morethan60(X)∧male(X)) = 0.6, and referring to Table 3 above, P(cancer(X)|~patient(X)∧~familyHistory(X)∧~smoke(X)∧helicobacter(X)) = 0.1857, so the risk probability of record 8 in Fig. 5 is calculated as ((0.6)-(0.1857)) / (1-0.1857)= 0.5088 (i.e., 50.88%).
[0222] Therefore, since the calculated risk probability exceeds the risk judgment threshold of 50%, the probability inference attack detection unit (140) additionally determines one of male and morethan60 (age 60 or older) as an inference attack factor to be restricted, excluding the sensitive inference attack factor and the inferable logic inference attack factor. Record 8 in Table 5 shows an example in which morethan60 was determined as an inference attack factor to be restricted.
[0223] And the probability inference attack detection unit (140) recalculates the risk probability for record 8 of FIG. 5 using the above mathematical expression 19 and determines whether the risk probability exceeds the risk judgment threshold (50%). That is, after additionally restricting morethan60 and calculating the risk probability for record 8 of FIG. 5 with reference to Table 3, the risk probability is 0.4043 (40.43%), which does not exceed the risk judgment threshold of 50%. Therefore, the probability inference attack detection unit (140) does not further determine the inference attack elements to be restricted according to the risk probability.
[0224] In addition, since the inferable logic threshold (τ) of the probability inference attack detection unit (140) is set to 1, it determines one addr among the inferable logic elements, maritalStatus and addr, as the inferable attack element to be restricted, as determined in the example of records 1 and 6. Record 8 of Table 5 also shows an example of restricting addr (address).
[0225] The probability inference attack control unit (160) outputs data attributes corresponding to the inference attack elements that have been decided to be subject to restriction processing among the inference attack elements included in the result data, as shown in Table 5.
[0226] Different DBMS as shown in Fig. 8 and Fig. 9 p1 and DBMS p2 Inference attack transaction t from (a,p1,q1) and t (b,p2,q2) Wow, the result data r (a,p1,q1) and r (b,p2,q2) In the case of , it will be obvious that inference control is performed as described above. In addition, different DBMSs are used by the same user (a). p1 and DBMS p2 Inference attack transaction t from (a,p1,q1) and t (a,p2,q2) Wow, the result data r (a,p1,q1) and r (a,p2,q2)It will be self-evident that inference control is carried out as described above in this case as well.
[0227] The probability inference attack detection unit (140) stores the inference attack elements that have been decided to be restricted and the inference attack elements to be provided as inference knowledge in the inference knowledge storage unit (150). However, as explained above, the sensitive inference attack threshold (ρ) x ) is determined to be restricted based on the inference attack element check set (ω in the 12th line of Equation 16) excluding the inference attack element determined to be restricted based on the inference attack element check set (δ in the 14th line of Equation 16), each result data record (r i,j ) is applied to perform restriction processing (lines 16 to 18 and 21 of Equation 16), and the next result data record (r i,j+1 ) does not affect the restriction processing (lines 11 and 16 of Equation 16), and also the following result data (r i+1 ) so as not to affect the restriction processing for the reasoning attack element that has been restricted (i.e., not including δ in the 20th line of mathematical expression 16), thereby storing it in the reasoning knowledge storage unit (150) so as not to be included in the reasoning attack element that has been restricted (i.e., not including δ in the 20th line of mathematical expression 16), the effect of increasing data usability can be obtained.
[0228] And, when a probability inference attack is detected, the probability inference attack detection unit (140) notifies the security manager terminal that the inference attack has been detected and restricted, and provides reporting information about the content.
[0229] The above limitation processing is d of the result data as in 1101 of Fig. 10. l or d of 1201 of Fig. 11 h The corresponding data attribute information is masked or anonymized, or the data attribute (d) is removed from the result data as in 1102 of FIG. 10. l ) or data attribute (d) of 1202 of Fig. 11 h ) may be applied to remove the processing.
[0230] Figure 12 is a flowchart illustrating a DB inference attack control method according to the present invention.
[0231] Referring to FIG. 12, the probability inference control unit (20) provides an inference logic setting interface means to the security manager terminal through the inference setting unit (110) to set the inference logic including the probability inference attack logic, and stores the set probability inference attack logic as inference knowledge in the inference knowledge storage unit (150) (S111). The above inference logic setting includes a probability model, probability logic, probability inference attack logic, inference possible logic, and a sensitive inference attack element subset (s). x ), risk judgment threshold (λ), sensitive inference attack factor threshold (ρ x ), and the inference logic threshold (τ) is set.
[0232] When the above setting is completed, the probability inference control unit (20) generates inference attack elements by the probability inference attack logic and inference possible logic generated through the inference attack element generation unit (230) of the inference logic setting unit (110), and generates an inference attack element set (E) for the inference attack elements and provides it to the inference attack element extraction units (120) (S113).
[0233] When the probability inference attack logic is set and the inference attack elements are set, the probability inference control unit (20) monitors whether result data is input from the DBMS (30) through the inference attack element extraction units (120) (S115).
[0234] When the result data is input, the probability inference control unit (20) checks whether each inference attack element of the preset inference attack element set is included in the result data through the inference attack element extraction units (120), and if included, extracts the corresponding inference attack element and generates an inference attack transaction (t) composed of the extracted inference attack elements. (u,p,q) ) is generated, and output to the inference attack sequence configuration unit (130) (S117).
[0235] The above inference attack transaction (t (u,p,q)) is input, the probability inference control unit (20) extracts the inference attack transaction (t) input from a plurality of inference attack element extraction units (120) through the inference attack ordering configuration unit (130). (u,p,q) ) are serialized in the order of the result data input time and output to the probability inference attack detection unit (140) (S119).
[0236] The probability inference control unit (20) detects the inference attack elements of the serially ordered inference attack transaction input from the inference attack sequencing unit (130) through the probability inference attack detection unit (140) and the inference attack element check set including the previously provided inference attack elements registered in the inference knowledge, and the inference possible logic (c x ) and sensitive inference attack subset (s x ) monitors whether there is an inference attack element matching one or more of them (S121).
[0237] At this time, some of the inference attack elements in the inference attack element check set for the input inference attack transaction are inferable logic (c x ) and sensitive inference attack subset (s x ) is matched to the inference attack element, the probability inference control unit (20) checks the inference attack element check set through the probability inference attack detection unit (140) to determine the inference attack element among the inference attack elements included in the result data, which is the inference possible logic (c). x ) and sensitive inference attack subset (s x ) is determined based on each threshold from the inference attack elements that can be configured (S123). At this time, among the inference attack elements of the inference attack element check set, the inference-capable logic (c) is determined. x ) to check if there is an inference attack element matching the inference logic (c x ), determining the inference attack element to be limited according to the inference possible logic threshold (τ) may be performed as in S121 to S123 described above, or may be configured to be performed before outputting the result data (i.e., before step S131 and after step S137 below).
[0238] When the inference attack elements to be restricted are determined or there are no inference attack elements to be restricted by the inference-capable logic and sensitive inference attack subset, the probability inference control unit (20) determines whether an inference knowledge update element exists through the probability inference attack detection unit (140) (S124). In other words, the probability inference attack detection unit (140) determines whether there are inference attack elements to be newly restricted or newly provided to the inquirer.
[0239] If there is a newly restricted or newly provided inference attack element, the probability inference attack detection unit (140) stores the inference attack element as inference knowledge in the inference knowledge storage unit (150) to update the inference knowledge (S125).
[0240] The above probability inference attack detection unit (140) calculates the probability of an inference attack risk in the state of the inference attack element check set, that is, the inference attack element check set excluding the inference attack elements that are determined to be subject to limited processing by the inference possible logic and sensitive inference attack subset among the inference attack elements included in the result data (S127).
[0241] Once the risk probability is calculated, the probability inference attack detection unit (140) checks whether the calculated risk probability exceeds a preset risk judgment threshold (λ) and determines whether to further restrict the inference attack element (S129).
[0242] If the risk probability as a result of the judgment does not exceed the risk judgment threshold, the probability inference attack detection unit (140) determines the sensitive inference attack element threshold (ρ x ) and the inference-possible logic threshold (τ), if there are inference attack elements that have already been restricted, the restricted result data is output by reflecting them (S131).
[0243] On the other hand, if the risk probability of the judgment result exceeds the risk judgment threshold, the probability inference attack detection unit (140) determines that an inference attack has been detected, and the probability inference attack logic (α) x) After additionally determining the inference attack elements to be restricted (S133), the occurrence of an inference attack is notified to the security manager terminal and reporting information on the content is provided (S135).
[0244] The probability inference control unit (20) controls the risk judgment threshold (λ) and the sensitive inference attack element threshold (ρ) through the probability inference attack control unit (160). x ) and the inferable logic threshold (τ), among the plurality of data attributes that constitute the result data, the data attribute information corresponding to the inference attack element that has been decided to be subject to the restriction processing is restricted (S137).
[0245] The above probability inference control unit (20) provides the result data processed through the probability inference attack control unit (160) to the corresponding query terminal unit through the input / output unit (10) (S139).
[0246] The above probability inference attack control unit (160) generates an inference attack log including the results of detection and limitation processing of an inference attack, and stores the generated inference attack log in the inference attack log storage unit (170) (S141).
[0247] Meanwhile, those skilled in the art will readily understand that the present invention is not limited to the aforementioned typical preferred embodiments, but can be implemented by various improvements, modifications, substitutions, or additions without departing from the spirit of the present invention. If such improvements, modifications, substitutions, or additions fall within the scope of the appended claims, the technical ideas thereof shall also be deemed to belong to the present invention.
[0248] [Explanation of symbols]
[0249] 10: Input / output unit 20: Probability inference control unit
[0250] 30: Database Management System (DBMS)
[0251] 40: Database (DB) 110: Inference settings section
[0252] 120: Inference attack element extraction section 130: Inference attack sequence configuration section
[0253] 140: Probabilistic inference attack detection unit 150: Inference knowledge storage unit
[0254] 160: Probabilistic inference attack control unit 170: Inference attack log storage unit
[0255] 210: Inference logic setting interface section
[0256] 220: Inference logic generation unit 221: Probability logic generation unit
[0257] 222: Inferable logic generation unit 223: Probabilistic inference attack logic generation unit
[0258] 230: Inference attack element generation section 240: Sensitive inference attack subset setting section
[0259] 250: Threshold setting section
Claims
1. An input / output unit that receives and outputs queries from multiple query terminals, receives result data in response to the input queries, and provides the data to the corresponding query terminal; At least one database (DB) including a plurality of data attributes, wherein at least one of the DBs includes a sensitive data attribute set as sensitive information to be protected, and at least one DBMS that searches the DB for a query word input from the input / output unit and generates and outputs result data as a search result; and A DB inference attack control device based on probability logic, characterized by including a probability inference control unit that sets inference knowledge including inference attack elements corresponding to data attributes from which the sensitive information can be probabilistically inferred, a probability model composed of probabilistic models of the inference attack elements, probability logic, and probability inference attack logic, calculates a risk probability that the sensitive information can be inferred by inference attack elements extracted from result data input from the DBMS with reference to the inference knowledge, determines that an inference attack has been detected if the calculated risk probability exceeds a risk judgment threshold, and restricts and processes data attribute information corresponding to at least one or more inference attack elements from which the sensitive information can be inferred among the inference attack elements included in the result data from which the inference attack has been detected, and then transmits the data to a corresponding queryer terminal through the input / output unit.
2. In paragraph 1, The above probability inference control unit, An inference knowledge storage unit that stores inference knowledge including inference attack elements corresponding to the above probability inference attack logic and data attributes provided to the query terminal; An inference setting unit which receives from a security manager through a security manager terminal one or more data attributes capable of probabilistically inferring the sensitive information configured in a DB and a probability value for a data attribute having a probability of inferring the sensitive information among the data attributes, generates a probability model, probability logic and probability inference attack logic including the one or more data attributes and probability, and stores them as inference knowledge in the inference knowledge storage unit, and sets the data attributes included in the probability inference attack logic as inference attack elements and outputs an inference attack element set including the set inference attack elements; An inference attack element extraction unit that receives and sets a set of inference attack elements from the above-mentioned inference setting unit, extracts inference attack elements corresponding to the set of inference attack elements from result data input from DBMSs, and generates and outputs an inference attack transaction composed of the extracted inference attack elements; A probabilistic inference attack detection unit configured to receive the above inference attack transaction as input, form an inference attack element check set including inference attack elements included in the above inference attack transaction and inference attack elements provided to the query terminal stored in the inference knowledge storage, and check whether the inference attack elements of the above inference attack element check set satisfy any one of the probabilistic inference attack logics of the above inference knowledge storage, and calculate a risk probability that the sensitive information can be inferred by the inference attack elements extracted from the inference attack element check set with reference to the probabilistic inference attack logic, and determine that the inference attack has been detected if the calculated risk probability exceeds a risk judgment threshold, and output restriction processing request information requesting restriction processing for any one or more of the inference attack elements of the corresponding inference attack transaction when the inference attack is detected; and A DB inference attack control device based on probability logic, characterized by including a probability inference attack control unit that, when inputting restriction processing request information from the above probability inference attack detection unit, restricts and processes data attributes corresponding to inference attack elements of the input restriction processing request information among data attributes included in result data corresponding to an inference attack transaction in which an inference attack has been detected, and provides the data to the corresponding query terminal through an input / output unit.
3. In paragraph 2, The above probability inference control unit, Further comprising an inference attack ordering component that serially orders and outputs a plurality of inference attack transactions input from the above inference attack element extraction component, The above probability inference attack detection unit is, A DB inference attack control device based on probability logic, characterized in that it detects an inference attack by the above serially ordered inference attack transactions.
4. In paragraph 2, The above inference setting part is, An inference logic generation unit that receives one or more data attributes from which the sensitive information configured in the DB can be inferred through the security manager terminal and a probability value for the data attribute having a probability of inferring the sensitive information among the data attributes, and generates a probability model, probability logic and probability inference attack logic including the one or more data attributes and probability and stores them as inference knowledge in the inference knowledge storage unit; and A DB inference attack control device based on probability logic, characterized by including an inference attack element generation unit that sets data properties included in the above probability inference attack logic as inference attack elements and outputs them.
5. In paragraph 4, The above inference logic generation unit is, A probability logic generation unit that receives one or more data attributes directly related to the sensitive information configured in the DB from the security manager through the security manager terminal and from which the sensitive information can be inferred, and receives a probability of inferring the sensitive information from the one or more data attributes, and generates a probability logic and a probability calculation value for the probability logic based on a probability model and conditional probability by data attribute, and stores the results in the inference knowledge storage unit; A probability inference attack logic generation unit that generates a probability inference attack logic including the probability logic generated in the above probability logic generation unit as one of the above inference knowledge and stores it in the above inference knowledge storage unit; and A DB inference attack control device based on probability logic, characterized by including an inference logic generation unit which receives one or more data attributes capable of increasing the accuracy of an inference attack on the above sensitive information, generates an inference logic including the one or more data attributes, generates an extended inference attack logic by combining the inference logic and the probabilistic inference attack logic, and then stores the extended inference attack logic as inference knowledge in the inference knowledge storage unit.
6. In paragraph 5, The above inference setting part is, A DB inference attack control device based on probability logic, characterized by further including a sensitive inference attack subset setting unit that receives, from a security manager through a security manager terminal, inference attack elements of the probabilistic inference attack logic that have a more sensitive effect on inferring the sensitive information than other inference attack elements, and registers and sets them as a sensitive inference attack subset.
7. In paragraph 6, The above inference setting part is, When a request for threshold setting is made from the security manager terminal, a risk judgment threshold (λ) for detecting inference attacks by probability inference attack logic, and a sensitive inference attack element threshold (ρ), which is the number of inference attack elements to be limitedly processed among inference attack elements when detecting the sensitive inference attack subset, are provided. x ) and a threshold setting unit for receiving an inferable logic threshold (τ), which is the number of inferential attack elements to be limitedly processed among the inferable logic's inferential attack elements when detecting the inferable logic, and storing it in an inferential knowledge storage unit and setting it. A DB inference attack control device based on probability logic.
8. In paragraph 7, The above probability inference attack detection unit is, For each inference attack transaction record constituting the above inference attack transaction, the inference attack element check set is generated including the inference attack elements included in the above inference attack transaction record and the previously provided inference attack elements stored in the inference knowledge storage, and if a set of inference attack elements corresponding to a sensitive inference attack subset exists in the inference attack element check set, the sensitive inference attack element threshold (ρ) is calculated. x ) determines the sensitive inference attack elements to be restricted, and stores the sensitive inference attack elements determined to be restricted in the inference knowledge storage as the sensitive inference attack elements that have already been restricted, and then, in the inference attack element check set generated thereafter, the sensitive inference attack elements that have already been restricted are removed from the inference attack element set, and the threshold value (ρ) of the sensitive inference attack elements is used. x ) determines the sensitive inference attack factors to be newly restricted and processed, In the above-mentioned inference attack element check set, the sensitive inference attack element to be restricted is removed, and the sensitive inference attack element to be restricted is removed from the inference attack element check set and the probability inference attack logic, thereby generating the inference attack element determination target set, and based on the inference attack element check set, the risk probability that the sensitive information can be inferred by the inference attack elements constituting the probability inference attack logic is calculated, and if the calculated risk probability exceeds the risk judgment threshold (λ), the inference attack is considered to have been detected, and one of the inference attack elements of the inference attack element determination target set is determined to be restricted, and the inference attack elements determined to be restricted are respectively removed and updated from the inference attack element check set and the inference attack element determination target set, and the risk probability is calculated based on the updated inference attack element check set, but until the calculated risk probability does not exceed the risk judgment threshold, one of the inference attack elements of the inference attack element determination target set is determined as the inference attack element to be restricted. A DB inference attack control device based on probability logic characterized by:
9. In paragraph 8, The above probability inference attack detection unit is, A DB inference attack control device based on probability logic, characterized in that it determines whether the inference attack element check set above includes inference attack elements constituting inferenceable logic, and if it is determined that inferenceable logic is configured, it determines inference attack elements to be restricted and processed among the inference attack elements constituting the inferenceable logic according to the inferenceable logic threshold (τ).
10. In paragraph 9, The above probability inference attack detection unit is, In calculating the risk probability that the sensitive information can be inferred by the inference attack elements that constitute the probability inference attack logic based on the inference attack element check set from which the sensitive inference attack elements to be restricted are removed, A DB inference attack control device based on probability logic, characterized in that the risk probability is calculated in real time when the inference attack is detected, or the probability for the probability logic is calculated in advance based on the conditional probability for each probability model and data attribute and stored in the inference knowledge storage, and the previously stored probability calculation value corresponding to the probability inference attack logic is output from the inference knowledge storage and referenced based on the inference attack element check set when the inference attack is detected.
11. In paragraph 2, The above probability inference attack control unit is, A DB inference attack control device based on probability logic, characterized in that the data attribute information corresponding to the inference attack element to be restricted among the result data is masked or anonymized, or the data attribute information is removed from the result data by performing a removal process to restrict the processing of the data attribute information.
12. A DB search process in which one or more DBMSs that manage at least one DB containing sensitive information to be protected among one or more DBs storing information including multiple data attributes perform a search for a query word input from the DB and generate and output result data according to the search results; and A DB inference attack control method based on probability logic, characterized in that it includes a probability inference control process in which a probability inference control unit sets inference knowledge including inference attack elements corresponding to data attributes from which the sensitive information can be probabilistically inferred, a probability model composed of the probability of the inference attack elements, probability logic, and probability inference attack logic, calculates a risk probability that the sensitive information can be inferred by inference attack elements extracted from result data input from the DBMS with reference to the inference knowledge, determines that an inference attack has been detected if the calculated risk probability exceeds a risk judgment threshold, and restricts and processes data attributes corresponding to at least one or more inference attack elements from which the sensitive information can be inferred among the inference attack elements included in the result data from which the inference attack has been detected, and transmits the data to a corresponding queryer terminal through an input / output unit.
13. In paragraph 12, The above probabilistic inference control process is, An inference setting step in which the above probability inference control unit receives, from a security manager terminal unit through an inference setting unit, one or more data attributes capable of probabilistically inferring the sensitive information configured in a DB, and a probability value for a data attribute having a probability of inferring the sensitive information among the data attributes, generates a probability model, probability logic and probability inference attack logic including the one or more data attributes and probability, and stores them as inference knowledge in an inference knowledge storage unit, and sets the data attributes included in the probability inference attack logic as inference attack elements and outputs an inference attack element set including the set inference attack elements; An inference attack element extraction step in which the above probability inference control unit receives the set of inference attack elements from the inference setting unit, inputs the set of inference attack elements into the inference attack element extraction unit and sets it, and extracts inference attack elements corresponding to the set of inference attack elements from result data input from DBMSs through the inference attack element extraction unit, and generates and outputs an inference attack transaction composed of the extracted inference attack elements; A probabilistic inference attack detection step in which the probabilistic inference control unit receives the inference attack transaction through the probabilistic inference attack detection unit, configures an inference attack element check set including inference attack elements included in the inference attack transaction and inference attack elements provided to the query terminal stored in the inference knowledge storage unit, examines whether the inference attack elements of the inference attack element check set satisfy any one of the probabilistic inference attack logics of the inference knowledge storage unit, calculates a risk probability that the sensitive information can be inferred by the inference attack elements of the inference attack element check set with reference to the probabilistic inference attack logic, and determines that an inference attack is detected if the calculated risk probability exceeds a risk judgment threshold, and outputs restriction processing request information requesting restriction processing for any one or more of the inference attack elements of the corresponding inference attack transaction when the inference attack is detected; and A DB inference attack control method based on probability logic, characterized in that it includes a probabilistic inference attack control step in which, when the probabilistic inference control unit receives restriction processing request information from the probabilistic inference attack detection unit through the probabilistic inference attack control unit, the probabilistic inference attack control unit restricts and processes data attributes corresponding to inference attack elements of the input restriction processing request information among data attributes included in result data corresponding to an inference attack transaction in which an inference attack has been detected, and provides the data attributes to the corresponding query terminal unit through the input / output unit.
14. In paragraph 13, The above probabilistic inference control process is, The above probability inference control unit further includes an inference attack ordering configuration step for serially ordering and outputting a plurality of inference attack transactions input from the inference attack element extraction unit through the inference attack ordering configuration unit, A DB inference attack control method based on probability logic, characterized in that the probability inference attack control unit, when inputting restriction processing request information from the probability inference attack detection unit in the probability inference attack control step, restricts and processes data attributes corresponding to inference attack elements of the input restriction processing request information among data attributes of the result data corresponding to inference attack transactions in which an inference attack has been detected, and provides the data attributes to the corresponding query terminal through the input / output unit.
15. In paragraph 13, The above inference setting step is, An inference logic generation step in which the above-mentioned inference setting unit receives from the security manager terminal unit, through the inference logic generation unit, one or more data attributes capable of inferring the sensitive information configured in the DB, and a probability value for a data attribute having a probability of inferring the sensitive information among the data attributes, and generates a probability model, probability logic, and probability inference attack logic including the one or more data attributes and probability, and stores them as inference knowledge in the inference knowledge storage unit; and A DB inference attack control method based on probability logic, characterized in that the above-mentioned inference setting unit includes an inference attack element generation step for setting data properties included in the above-mentioned probability inference attack logic as inference attack elements and outputting them through an inference attack element generation unit.
16. In paragraph 15, The above inference logic generation step is, A probability logic generation step in which the above-mentioned inference logic generation unit receives from a security manager terminal unit, through a probability logic generation unit, one or more data attributes that are directly related to the sensitive information configured in the DB and can infer the sensitive information, and receives a probability of inferring the sensitive information from the one or more data attributes, and generates a probability logic and a probability calculation value for the probability logic based on a probability model and conditional probability for each data attribute, and stores the same in the inference knowledge storage unit; A probability inference attack logic generation step in which the above-mentioned inference logic generation unit generates a probability inference attack logic including the probability logic generated by the above-mentioned probability logic generation unit as one of the above-mentioned inference knowledge through the probability inference attack logic generation unit and stores it in the above-mentioned inference knowledge storage unit; and A DB inference attack control method based on probability logic, characterized in that it includes an inference logic generation step in which the inference logic generation unit receives one or more data attributes that can increase the accuracy of an inference attack on the sensitive information through the inference possible logic generation unit, generates an inference possible logic including the one or more data attributes, and generates an extended inference attack logic by combining the inference possible logic and the probabilistic inference attack logic, and then stores the extended inference attack logic as inference knowledge in the inference knowledge storage unit.
17. In paragraph 15, The above inference setting step is, A DB inference attack control method based on probability logic, characterized in that the above-mentioned inference setting unit further includes a sensitive inference attack subset setting step in which, from a security manager terminal, an inference attack element that has a more sensitive effect on inferring the sensitive information than other inference attack elements among the inference attack elements of the probability inference attack logic is input and set as a sensitive inference attack subset.
18. In paragraph 16, The above inference setting step is, The above inference setting unit further includes a sensitive inference attack subset setting step in which, through the sensitive inference attack subset setting unit, the security manager terminal receives an inference attack element that has a more sensitive effect on inferring the sensitive information than other inference attack elements among the inference attack elements of the probability inference attack logic and registers and sets it as a sensitive inference attack subset. The above inference setting step is, When the above inference setting unit requests threshold setting from the security manager terminal, the threshold setting unit detects a risk judgment threshold (λ) for inference attacks by probability inference attack logic, and the sensitive inference attack element threshold (ρ), which is the number of inference attack elements to be limitedly processed among inference attack elements when detecting the sensitive inference attack subset. x ) and a threshold setting step of receiving an inferable logic threshold (τ), which is a number of inferential attack elements to be limitedly processed among the inferable logic's inferential attack elements when detecting the inferable logic, and storing it in an inferential knowledge storage unit and setting it. A DB inference attack control method based on probability logic.
19. In Article 18, The above probabilistic inference attack detection step is The above probabilistic inference attack detection unit calculates the inference attack element check set including the inference attack elements included in the inference attack transaction record and the previously provided inference attack elements stored in the inference knowledge storage unit for each inference attack transaction record constituting the inference attack transaction, and if a set of inference attack elements corresponding to a sensitive inference attack subset exists in the inference attack element check set, the sensitive inference attack element threshold (ρ) x ) determines the sensitive inference attack elements to be restricted, and stores the sensitive inference attack elements determined to be restricted in the inference knowledge storage as the sensitive inference attack elements that have already been restricted, and then, in the inference attack element check set generated thereafter, the sensitive inference attack elements that have already been restricted are removed from the inference attack element set, and the threshold value (ρ) of the sensitive inference attack elements is used. x ) to determine the sensitive inference attack factors to be newly restricted and processed; An inference attack detection step in which the above-mentioned probability inference attack detection unit removes the sensitive inference attack elements to be restricted from the above-mentioned probability inference attack element check set, removes the sensitive inference attack elements to be restricted from the above-mentioned probability inference attack logic from the above-mentioned probability inference attack element check set, and calculates the risk probability that sensitive information can be inferred based on the above-mentioned probability inference attack element check set, and considers the inference attack to be detected if the above-mentioned calculated risk probability exceeds the risk judgment threshold (λ); and A DB inference attack control method based on probability logic, characterized by including a first restricted inference attack element determination step of determining, when the above probabilistic inference attack detection unit determines that the inference attack has been detected, any one of the inference attack elements of the inference attack element determination target set to be restricted, removing and updating the inference attack elements determined to be restricted from the inference attack element check set and the inference attack element determination target set, and calculating a risk probability based on the updated inference attack element check set, determining any one of the inference attack elements of the inference attack element determination target set as the inference attack element to be restricted until the calculated risk probability does not exceed the risk judgment threshold.
20. In paragraph 19, The above probabilistic inference attack detection step is: A DB inference attack control method based on probability logic, characterized in that the above probability inference attack detection unit further includes a second restricted inference attack element determination step of determining inference attack elements to be restricted among inference attack elements constituting the inferenceable logic according to the inferenceable logic threshold (τ) if it is determined that the inferenceable logic is configured.
21. In paragraph 19, The above probabilistic inference attack detection step is: In calculating the risk probability that the sensitive information can be inferred by the inference attack elements constituting the probability inference attack logic based on the inference attack element check set from which the sensitive inference attack elements to be restricted have been removed by the above probability inference attack detection unit, The above risk probability is calculated in real time when an inference attack is detected, or the probability for the probability logic is calculated in advance based on the conditional probability for each probability model and data attribute and stored in the inference knowledge storage, and when the inference attack is detected, the stored probability calculation value corresponding to the probability inference attack logic is output from the inference knowledge storage and referenced. A DB inference attack control method based on probability logic.
22. In paragraph 13, A DB inference attack control method based on probability logic, characterized in that, in the above probability inference attack control step, the probability inference attack control unit performs masking or anonymization processing on data attribute information corresponding to inference attack elements to be restricted among result data, or performs removal processing to remove the corresponding data attribute information from the result data, thereby restricting the processing of the data attribute information.
Citation Information
Patent Citations
Computer packaging system, and secure path selection method utilizing network evaluation
JP2016111664A
Personal information de-identification system with security function and method thereof
KR101859636B1
System for prenventing inner users from leaking the personal information by returnning results and the detection of anomaly pattern
KR1020120007841A
KR20230083702A