Netinfo Security ›› 2021, Vol. 21 ›› Issue (10): 48-53.doi: 10.3969/j.issn.1671-1122.2021.10.007

Previous Articles     Next Articles

A Security Management Framework for Data Sensitivity and Multidimensional Classification

LIU Hong1,2(), ZHANG Yuejin3, ZHAO Wenxia4, YANG Mu4   

  1. 1. Run Technologies Co., Ltd. Beijing, Beijing 100192, China
    2. Beijing Cyberspace Data Analysis and Applied Engineering Technology Research Center, Beijing 100192, China
    3. Smart City College, Beijing Union University, Beijing 100101, China
    4. Beijing Municipal Public Security Bureau, Beijing 100055, China
  • Received:2021-06-15 Online:2021-10-10 Published:2021-10-14
  • Contact: LIU Hong E-mail:liuhong@bjrun.com

Abstract:

In view of there has been no consensus on the standard and the technical architecture of data sensitivity and classification management, and conventional tools to realize data sensitivity and classification have very limited expressive power, a framework for expressing and computing data sensitivity and multidimensional data classification was proposed. The method was based on a declarative logic programming language and was capable of defining and analyzing data sensitivity and classification with fine granularity and high efficiency. Firstly, in terms of expression ability and complexity, besides supported conventional security labels, sensitivity and classification assigned not on data records, or parameterized, or concerning multiple data resources could also be expressed and computed. Then based on sensitivity and classification, examples were given to show the expressiveness and complexity of the method. Various data security analysis and management mechanisms could be implemented on the same framework. In addition, utilizing the declarative nature of the language, realizing data security on existing systems incurs low overhead to performance and was transparented to underlying computation and storage details, which was beneficial to system migration and optimization, could reduce the impact of security mechanism on system performance, and facilitates the deployment of data sensitivity and classification-based security mechanisms.

Key words: data security, sensitivity and classification, logic programming, big data

CLC Number: