Balancing Security and Performance for Enhancing Data Privacy in Data Warehouses

被引:7
|
作者
Santos, Ricardo Jorge [1 ]
Bernardino, Jorge [2 ]
Vieira, Marco [1 ]
机构
[1] Univ Coimbra, CISUC DEI FCTUC, Coimbra, Portugal
[2] Polytech Inst Coimbra, CISUC DEIS ISEC, Coimbra, Portugal
关键词
Data warehousing; Data masking; Data obfuscation; Data encryption; Data privacy; Data security;
D O I
10.1109/TrustCom.2011.33
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Data Warehouses (DWs) store the golden nuggets of the business, which makes them an appealing target. To ensure data privacy, encryption solutions have been used and proven efficient in their security purpose. However, they introduce massive storage space and performance overheads, making them unfeasible for DWs. We propose a data masking technique for protecting sensitive business data in DWs that balances security strength with database performance, using a formula based on the mathematical modular operator. Our solution manages apparent randomness and distribution of the masked values, while introducing small storage space and query execution time overheads. It also enables a false data injection method for misleading attackers and increasing the overall security strength. It can be easily implemented in any DataBase Management System (DBMS) and transparently used, without changes to application source code. Experimental evaluations using a real-world DW and TPC-H decision support benchmark implemented in leading commercial DBMS Oracle 11g and Microsoft SQL Server 2008 demonstrate its overall effectiveness. Results show substantial savings of its implementation costs when compared with state of the art data privacy solutions provided by those DBMS and that it outperforms those solutions in both data querying and insertion of new data.
引用
收藏
页码:242 / 249
页数:8
相关论文
共 50 条
  • [1] Enhancing Data Warehouses Security
    Alkhubouli, Muhanad A.
    Lala, Hany M.
    AlHabshy, AbdAllah A.
    ElDahshan, Kamal A.
    [J]. International Journal of Advanced Computer Science and Applications, 2024, 15 (03) : 574 - 580
  • [2] Enhancing and simplifying data security and privacy for multitiered applications
    Rjaibi, Walid
    Hammoudeh, Mohammad
    [J]. JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2020, 139 : 53 - 64
  • [3] Enhancing IoT Data Security: Using the Blockchain to Boost Data Integrity and Privacy
    Eghmazi, Ali
    Ataei, Mohammadhossein
    Landry, Rene, Jr.
    Chevrette, Guy
    [J]. IOT, 2024, 5 (01): : 20 - 34
  • [4] Incorporating Privacy Support into Clinical Data Warehouses
    Landberg, Anders H.
    Grain, Heather
    Rahayu, J. Wenny
    Pardede, Eric
    [J]. ELECTRONIC JOURNAL OF HEALTH INFORMATICS, 2009, 4 (01):
  • [5] Balancing data protection and privacy - The case of information security sensor systems
    Naarttijarvi, Markus
    [J]. COMPUTER LAW & SECURITY REVIEW, 2018, 34 (05) : 1019 - 1038
  • [6] Privacy and Data Security
    Gaff, Brian M.
    Smedinghoff, Thomas J.
    Sor, Socheth
    [J]. COMPUTER, 2012, 45 (03) : 8 - 10
  • [7] Data protection - Security: Data security - The key to privacy
    Carey, Peter
    Berry, David
    [J]. Computer Law and Security Report, 2002, 18 (02): : 112 - 113
  • [8] Data-centric security: Integrating data privacy and data security
    Hennessy, S. D.
    Lauer, G. D.
    Zunic, N.
    Gerber, B.
    Nelson, A. C.
    [J]. IBM JOURNAL OF RESEARCH AND DEVELOPMENT, 2009, 53 (02)
  • [9] Evaluation of Approaches for Modeling of Security in Data Warehouses
    Khajaria, Krishna
    Kumar, Manoj
    [J]. ADVANCES IN COMPUTING AND COMMUNICATIONS, PT 2, 2011, 191 : 9 - 18
  • [10] A security architecture for data privacy and security
    Weaver, Alfred C.
    [J]. ETFA 2005: 10TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION, VOL 1, PTS 1 AND 2, PROCEEDINGS, 2005, : 673 - 676