An estimate of the information a database contains and the quantification of the vulnerability of that database to compromise by inferential methods is discussed. Such a measure could be used to evaluate the deterrent value of extant protection methods and provide a measure of the potential for inferential compromise through the use of one of the known attack tools. The authors explore the use of the concept of entropy as defined for information by C.E. Shannon (1948; 1951), for the purpose of quantifying information content in a database and develop a measure of vulnerability based on entropy. Use of the measure, when exact disclosure through the use of a tracker is anticipated, is characterized for both static and dynamic databases at design and operational time
Published in:
Computer Security Applications Conference, 1990., Proceedings of the Sixth Annual
Date of Conference: 3-7 Dec 1990