• DocumentCode
    2458918
  • Title

    DRAGOON: An Information Accountability System for High-Performance Databases

  • Author

    Pavlou, Kyriacos E. ; Snodgrass, Richard T.

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Arizona, Tucson, AZ, USA
  • fYear
    2012
  • fDate
    1-5 April 2012
  • Firstpage
    1329
  • Lastpage
    1332
  • Abstract
    Regulations and societal expectations have recently emphasized the need to mediate access to valuable databases, even access by insiders. Fraud occurs when a person, often an insider, tries to hide illegal activity. Companies would like to be assured that such tampering has not occurred, or if it does, that it will be quickly discovered and used to identify the perpetrator. At one end of the compliance spectrum lies the approach of restricting access to information and on the other that of information accountability. We focus on effecting information accountability of data stored in high-performance databases. The demonstrated work ensures appropriate use and thus end-to-end accountability of database information via a continuous assurance technology based on cryptographic hashing techniques. A prototype tamper detection and forensic analysis system named DRAGOON was designed and implemented to determine when tampering(s) occurred and what data were tampered with. DRAGOON is scalable, customizable, and intuitive. This work will show that information accountability is a viable alternative to information restriction for ensuring the correct storage, use, and maintenance of databases on extant DBMSes.
  • Keywords
    authorisation; computer forensics; cryptography; database management systems; fraud; DBMSEes; DRAGOON; compliance spectrum; continuous assurance technology; cryptographic hashing technique; database forensic analysis safeguard of Arizona; fraud; high-performance databases; information accountability system; prototype tamper detection; tampering; Algorithm design and analysis; Companies; Databases; Forensics; Graphical user interfaces; Monitoring; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Data Engineering (ICDE), 2012 IEEE 28th International Conference on
  • Conference_Location
    Washington, DC
  • ISSN
    1063-6382
  • Print_ISBN
    978-1-4673-0042-1
  • Type

    conf

  • DOI
    10.1109/ICDE.2012.139
  • Filename
    6228200