Statistical Database Auditing Without Query Denial Threat

Published Online:https://doi.org/10.1287/ijoc.2014.0607

References

  • Adam NR, Wortmann JC (1989) Security-control methods for statistical databases: A comparative study. ACM Comput. Surveys 21:515–556.CrossrefGoogle Scholar
  • Agrawal S, Budetti P (2012) Physician medical identity theft. JAMA 307:459–460.CrossrefGoogle Scholar
  • Berkelaar AB, Jansen B, Roos K, Terlaky T (1996) Sensitivity analysis in (degenerate) quadratic programming. Technical Report 96-26, (Delft University of Technology, Delft, the Netherlands).Google Scholar
  • Castro J (2007) A shortest-paths heuristic for statistical data protection in positive tables. INFORMS J. Comput. 19:520–533.LinkGoogle Scholar
  • Chin FY (1978) Security in statistical databases for queries with small counts. ACM Trans. Database Systems 3:92–104.CrossrefGoogle Scholar
  • Chin FYL (1986) Security problems on inference control for sum, max, and min queries. J. ACM 33:451–464.CrossrefGoogle Scholar
  • Chin FYL, Özsoyoglu G (1981) Statistical database design. ACM Trans. Database Systems 6:113–139.CrossrefGoogle Scholar
  • Chin FYL, Özsoyoglu G (1982) Auditing and inference control in statistical databases. IEEE Trans. Software Engrg. 8:574–582.CrossrefGoogle Scholar
  • Chowdhury SD, Duncan GT, Krishnan R, Roehrig SF, Mukherjee S (1999) Disclosure detection in multivariate categorical databases: Auditing confidentiality protection through two new matrix operators. Management Sci. 45:1710–1723.LinkGoogle Scholar
  • Dantzig GB (1963) Linear Programming and Extensions (Princeton University Press, Princeton, NJ).CrossrefGoogle Scholar
  • Dinur I, Nissim K (2003) Revealing information while preserving privacy. Proc. Twenty-Second ACM Sympos. Principles Database Systems (ACM, New York), 202–210.CrossrefGoogle Scholar
  • Dobkin D, Jones AK, Lipton RJ (1979) Secure databases: Protection against user influence. ACM Trans. Database Systems 4:97–106.CrossrefGoogle Scholar
  • Dwork C (2008) Differential privacy: A survey of results. TAMC 4978:1–19.Google Scholar
  • Fischetti M, Salazar JJ (2001) Solving the cell suppression problem on tabular data with linear constraints. Management Sci. 47:1008–1027.LinkGoogle Scholar
  • Friedman AD, Hoffman LJ (1980) Towards a fail-safe approach to secure databases. IEEE Sympos. Security and Privacy, Oakland, CA.CrossrefGoogle Scholar
  • Fung BCM, Wang K, Chen R, Yu PS (2010) Privacy-preserving data publishing: A survey of recent developments. ACM Comput. Surveys 42:14:1–14:53.CrossrefGoogle Scholar
  • Garey MR, Johnson DS (1979) Computers and Intractability: A Guide to the Theory of NP-Completeness (W.H. Freeman, New York).Google Scholar
  • Garfinkel R, Gopal R, Goes P (2002) Privacy protection of binary confidential data against deterministic, stochastic, and insider threat. Management Sci. 48:749–764.LinkGoogle Scholar
  • Goldfarb D, Scheinberg K (1999) On parametric semidefinite programming. Appl. Numer. Math. 29:361–377.CrossrefGoogle Scholar
  • Kadane JB, Krishnan R, Shmueli G (2006) A data disclosure policy for count data based on the COM-Poisson distribution. Management Sci. 52:1610–1617.LinkGoogle Scholar
  • Kaelber DC, Jha AK, Johnston D, Middleton B, Bates DW (2008) A research agenda for personal health records (phrs). J. Amer. Medical Informatics Assoc. 15:729–736.CrossrefGoogle Scholar
  • Kenthapadi K, Mishra N, Nissim K (2005) Simulatable auditing. Proc. Twenty-Fourth ACM Sympos. Principles Database Systems (ACM, New York), 118–127.CrossrefGoogle Scholar
  • Kleinberg JM, Papadimitriou CH, Raghavan P (2003) Auditing Boolean attributes. J. Comput. Syst. Sci. 66:244–253.CrossrefGoogle Scholar
  • Kumar R, Gopal R, Garfinkel R (2010) Freedom of privacy: Anonymous data collection with respondent-defined privacy protection. INFORMS J. Comput. 22:471–481.LinkGoogle Scholar
  • Lee S, Genton MG, Arellano-Valle RB (2010) Perturbation of numerical confidential data via skew-t distributions. Management Sci. 56:318–333.LinkGoogle Scholar
  • Li N, Li T, Venkatasubramanian S (2007) t-Closeness: Privacy beyond k-anonymity and l-diversity. Chirkova R, Dogac A, Tamerözsu M, Sellis TK, eds. Proc. 23rd IEEE Internat. Conf. Data Engrg. (IEEE Computer Society, Los Alamitos, CA), 106–115.CrossrefGoogle Scholar
  • Li X-B, Sarkar S (2006) Privacy protection in data mining: A perturbation approach for categorical data. Inform. Systems Res. 17:254–270.LinkGoogle Scholar
  • Li X-B, Sarkar S (2011) Protecting privacy against record linkage disclosure: A bounded swapping approach for numeric data. Inform. Systems Res. 22:774–789.LinkGoogle Scholar
  • Li X-B, Sarkar S (2013) Class-restricted clustering and microperturbation for data privacy. Management Sci. 59:796–812.LinkGoogle Scholar
  • Li Y, Lu H (2008) Disclosure analysis and control in statistical databases. ESORICS, Lecture Notes in Computer Science, Vol. 5283 (Springer, New York), 146–160.CrossrefGoogle Scholar
  • Li Y, Wang L, Jajodia S (2003) Preventing interval-based inference by random data perturbation. Proc. 2nd Internat. Conf. Privacy Enhancing Tech., San Francisco, 160–170.CrossrefGoogle Scholar
  • Lu H, Li Y (2008) Practical inference control for data cubes. IEEE Trans. Dependable Sec. Comput. 5:87–98.CrossrefGoogle Scholar
  • Lu H, Li Y, Atluri V, Vaidya J (2009) An efficient online auditing approach to limit private data disclosure. ACM Internat. Conf. Extending Database Tech. (ACM, New York), 636–647.CrossrefGoogle Scholar
  • Machanavajjhala A, Gehrke J, Kifer D, Venkitasubramaniam M (2006) l-Diversity: Privacy beyond k-anonymity. IEEE Internat. Conf. Data Engrg. (IEEE Computer Society, Los Alamitos, CA), 24.CrossrefGoogle Scholar
  • Malvestuto FM, Moscarini M (2006) Auditing sum-queries to make a statistical database secure. ACM Trans. Inform. System Security 33:451–464.Google Scholar
  • Matloff NS (1986) Another look at the use of noise addition for database security. IEEE Sympos. Security Privacy (IEEE Computer Society, Los Alamitos, CA), 173–181.CrossrefGoogle Scholar
  • Muralidhar K, Sarathy R (2006) Data shuffling—A new masking approach for numerical data. Management Sci. 52:658–670.LinkGoogle Scholar
  • Muralidhar K, Batra D, Kirs PJ (1995) Accessibility, security, and accuracy in statistical databases: The case for the multiplicative fixed data perturbation approach. Management Sci. 41:1549–1564.LinkGoogle Scholar
  • Muralidhar K, Parsa R, Sarathy R (1999) A general additive data perturbation method for database security. Management Sci. 45:1399–1415.LinkGoogle Scholar
  • Nabar SU, Marthi B, Kenthapadi K, Mishra N, Motwani R (2006) Towards robustness in query auditing. Proc. 32nd Internat. Conf. Very Large Data Bases, Seoul, Korea.Google Scholar
  • Nunez MA, Garfinkel RS, Gopal RD (2007) Stochastic protection of confidential information in databases: A hybrid of data perturbation and query restriction. Oper. Res. 55:890–908.LinkGoogle Scholar
  • Samarati P, Sweeney L (1998) Protecting privacy when disclosing information: k-anonymity and its enforcement through generalization and suppression. Technical report, SRI International, Menlo Park, CA.Google Scholar
  • Sarathy R, Muralidhar K, Parsa R (2002) Perturbing nonnormal confidential attributes: The Copula approach. Management Sci. 48:1613–1627.LinkGoogle Scholar
  • Schlorer J (1975) Confidentiality of statistical records: A threat-monitoring scheme for on line dialgoue. Methods Inform. Medicine 14:36–42.Google Scholar
  • Sweeney L (2002) k-anonymity: A model for protecting privacy. Internat. J. Uncertainty Fuzziness Knowledge-Based Systems 10:557–570.CrossrefGoogle Scholar
  • Vandenberghe L, Boyd S (1996) Semidefinite programming. SIAM Rev. 38:49–95.CrossrefGoogle Scholar
  • Vanderbei RJ (2008) Linear Programming: Foundations and Extensions, 3rd ed. (Springer-Verlag, New York).CrossrefGoogle Scholar
  • Wang L, Jajodia S, Wijesekera D (2004) Securing OLAP data cubes against privacy breaches. IEEE Sympos. Security Privacy (IEEE Computer Society, Los Alamitos, CA), 161–175.CrossrefGoogle Scholar
  • Wang L, Li Y, Wijesekera D, Jajodia S (2003) Precisely answering multi-dimensional range queries without privacy breaches. Eur. Sympos. Res. Comput. Security (Springer, New York), 100–115.CrossrefGoogle Scholar
INFORMS site uses cookies to store information on your computer. Some are essential to make our site work; Others help us improve the user experience. By using this site, you consent to the placement of these cookies. Please read our Privacy Statement to learn more.