On flow control mechanisms and their impacts upon statistical databases

The effect of mixing two or more independently designed data security policies has not been well analyzed. There has been concern that it may create unexpected violations. The authors show that the widely used *-property flow control policy in multi-level data security systems can contribute to the compromise of statistical databases. They further conclude that additions of unclassified data into a statistical database alone may undermine inference control policies and mechanisms. Fundamental insights obtained from this study must be taken into account during data security policy analysis and formulation.<<ETX>>