DocumentCode :
3147905
Title :
A portable implementation framework for intrusion-resilient database management systems
Author :
Smirnov, Alexey ; Chiueh, Tzi-cker
Author_Institution :
Dept. of Comput. Sci., SUNY, Stony Brook, NY, USA
fYear :
2004
fDate :
28 June-1 July 2004
Firstpage :
443
Lastpage :
452
Abstract :
An intrusion-resilient database management system is the one that is capable of restoring its consistency after being compromised by a malicious attack or a human error. More specifically, an intrusion-resilient mechanism helps to quickly repair a database by ifying the damage caused by malicious or erroneous transactions, while preserving the effects of unaffected legitimate transactions that take place between intrusions/errors and their detection. The goal of this project is to develop a portable implementation framework that can augment a commercial database management system with intrusion resilience without requiring any modifications to its internals. The intrusion resilience mechanism described in this paper significantly improves the availability of modern DBMSs by facilitating and sometimes even automating the post-intrusion damage repair process. In addition, it can be embodied in a reusable implementation framework, whose portability is demonstrated by its successful application to three different DBMSs: PostgreSQL, Oracle, and Sybase. Performance measurements on the fully operational prototypes under the TPC-C benchmark show that the run-time overhead of the intrusion-resilience mechanism is between 6% and 13%.
Keywords :
authorisation; database management systems; error detection; DBMS; Oracle; PostgreSQL; Sybase; TPC-C benchmark; database management systems; erroneous transaction; error detection; intrusion detection; intrusion-resilient mechanism; malicious attacks; malicious transaction; Availability; Computer errors; Computer science; Database systems; File servers; Hardware; Humans; Information systems; Resilience; Transaction databases;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems and Networks, 2004 International Conference on
Print_ISBN :
0-7695-2052-9
Type :
conf
DOI :
10.1109/DSN.2004.1311914
Filename :
1311914
Link To Document :
بازگشت