Qapla: Policy compliance for database-backed systems
Aastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg, Peter Druschel
摘要
Many database-backed systems store confidential data that is accessed on behalf of users with different privileges. Policies governing access are often fine-grained, being specific to users, time, accessed columns and rows, values in the database (e.g., user roles), and operators used in queries (e.g., aggregators, group by, and join). Today, applications are often relied upon to issue policy compliant queries or filter the results of non-compliant queries, which is vulnerable to application errors. Qapla provides an alternate approach to policy enforcement that neither depends on application correctness, nor on specialized database support. In Qapla, policies are specific to rows and columns and may additionally refer to the querier's identity and time, are specified in SQL, and stored in the database itself. We prototype Qapla in a database adapter, and evaluate it by enforcing applicable policies in the HotCRP conference management system and a system for managing academic job applications.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- Zeph: Cryptographic Enforcement of End-to-End Data PrivacyLukas Burkhalter, Nicolas Küchler, Alexander Viand, Hossein Shafagh 等OSDI 2021 · 被引用 35 次
- STORM: Refinement Types for Secure Web ApplicationsNico Lehmann, Rose Kunkel, Jordan Brown, Jean Yang 等OSDI 2021 · 被引用 21 次
- Blockaid: Data Access Policy Enforcement for Web ApplicationsWen Zhang, Eric Sheng, Michael Alan Chang, Aurojit Panda 等OSDI 2022 · 被引用 8 次
- General Data Protection Runtime: Enforcing Transparent GDPR Compliance for Existing ApplicationsDavid Klein, Benny Rolle, Thomas Barber, Manuel Karl 等CCS 2023 · 被引用 5 次
- Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage ArchitecturesHarshavardhan Unnibhavi, David Cerdeira, Antonio Barbalace, Nuno Santos 等SIGMOD 2022 · 被引用 5 次
它引用的顶会 Paper1
相关 Paper
- Thoth: Comprehensive Policy Compliance in Data Retrieval SystemsEslam Elnikety, Aastha Mehta, Anjo Vahldiek-Oberwagner, Deepak Garg 等USENIX Security 2016 · 被引用 30 次
- Sieve: A Middleware Approach to Scalable Access Control for Database Management SystemsPrimal Pappachan, Roberto Yus, Sharad Mehrotra, Johann-Christoph FreytagVLDB 2020
- Extracting Database Access-Control Policies from Web ApplicationsWen Zhang, Dev Bali, Jamison Kerney, Aurojit Panda 等OSDI 2026
- Excalibur: A Virtual Machine for Adaptive Fine-grained JIT-Compiled Query Execution based on VOILATim Gubner, Peter BonczVLDB 2023 · 被引用 10 次
- Ensuring Authorized Updates in Multi-user Database-Backed ApplicationsKevin Eykholt, Atul Prakash, Barzan MozafariUSENIX Security 2017 · 被引用 4 次
