• DocumentCode
    2415575
  • Title

    Multi-version attack recovery for workflow systems

  • Author

    Yu, Meng ; Liu, Peng ; Zang, Wanyu

  • Author_Institution
    Sch. of Inf. Sci. & Technol., Pennsylvania State Univ., University Park, PA, USA
  • fYear
    2003
  • fDate
    8-12 Dec. 2003
  • Firstpage
    142
  • Lastpage
    150
  • Abstract
    Workflow systems are popular in daily business processing. Since vulnerabilities cannot be totally removed from a system, recovery from successful attacks is unavoidable. We focus on attacks that inject malicious tasks into workflow management systems. We introduce practical techniques for on-line attack recovery, which include rules for locating damage and rules for execution order. In our system, an independent intrusion detection system reports identified malicious tasks periodically. The recovery system detects all damage caused by the malicious tasks and automatically repairs the damage according to dependency relations. Without multiple versions of data objects, recovery tasks may be corrupted by executing normal tasks when we try to run damage analysis and normal tasks concurrently. We address the problem by introducing multiversion data objects to reduce unnecessary blocking of normal task execution and improve the performance of the whole system. We analyze the integrity level and performance of our system. The analytic results demonstrate guidelines for designing such kinds of systems.
  • Keywords
    business data processing; security of data; system recovery; workflow management software; data object; intrusion detection system; multiversion attack recovery; on-line attack recovery; workflow management system; Access control; Application software; Computer crashes; Computer security; Guidelines; Intrusion detection; Performance analysis; Transaction databases; Workflow management software;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2003. Proceedings. 19th Annual
  • Print_ISBN
    0-7695-2041-3
  • Type

    conf

  • DOI
    10.1109/CSAC.2003.1254319
  • Filename
    1254319