• DocumentCode
    2529678
  • Title

    Database Isolation and Filtering against Data Corruption Attacks

  • Author

    Meng Yu ; Peng Liu

  • Author_Institution
    Western Illinois Univ., Macomb
  • fYear
    2007
  • fDate
    10-14 Dec. 2007
  • Firstpage
    97
  • Lastpage
    106
  • Abstract
    Various attacks (e.g., SQL injections) may corrupt data items in the database systems, which decreases the integrity level of the database. Intrusion detections systems are becoming more and more sophisticated to detect such attacks. However, more advanced detection techniques require more complicated analyses, e.g, sequential analysis, which incurs detection latency. If we have an intrusion detection system as a filter for all system inputs, we introduce a uniform processing latency to all transactions of the database system. In this paper, we propose to use a "unsafe zone" to isolate user\´s SQL queries from a "safe zone" of the database. In the unsafe zone, we use polyinstantiations and flags for the records to provide an immediate but different view from that of the safe zone to the user. Such isolation has negligible processing latency from the user\´s view, while it can significantly improve the integrity level of the whole database system and reduce the recovery costs. Our techniques provide different integrity levels within different zones. Both our analytical and experimental results confirm the effectiveness of our isolation techniques against data corruption attacks to the databases. Our techniques can be applied to database systems to provide multizone isolations with different levels of QoS.
  • Keywords
    SQL; data integrity; quality of service; query processing; security of data; transaction processing; SQL injections; SQL queries; data corruption attacks; database filtering; database isolation; database system transactions; integrity level; intrusion detections systems; quality of service; recovery cost reduction; sequential analysis; uniform processing latency; unsafe zone; Application software; Computer science; Computer security; Database systems; Delay; Educational institutions; Information filtering; Information filters; Intrusion detection; Transaction databases;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2007. ACSAC 2007. Twenty-Third Annual
  • Conference_Location
    Miami Beach, FL
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3060-4
  • Type

    conf

  • DOI
    10.1109/ACSAC.2007.18
  • Filename
    4412980