• DocumentCode
    3147905
  • Title

    A portable implementation framework for intrusion-resilient database management systems

  • Author

    Smirnov, Alexey ; Chiueh, Tzi-cker

  • Author_Institution
    Dept. of Comput. Sci., SUNY, Stony Brook, NY, USA
  • fYear
    2004
  • fDate
    28 June-1 July 2004
  • Firstpage
    443
  • Lastpage
    452
  • Abstract
    An intrusion-resilient database management system is the one that is capable of restoring its consistency after being compromised by a malicious attack or a human error. More specifically, an intrusion-resilient mechanism helps to quickly repair a database by ifying the damage caused by malicious or erroneous transactions, while preserving the effects of unaffected legitimate transactions that take place between intrusions/errors and their detection. The goal of this project is to develop a portable implementation framework that can augment a commercial database management system with intrusion resilience without requiring any modifications to its internals. The intrusion resilience mechanism described in this paper significantly improves the availability of modern DBMSs by facilitating and sometimes even automating the post-intrusion damage repair process. In addition, it can be embodied in a reusable implementation framework, whose portability is demonstrated by its successful application to three different DBMSs: PostgreSQL, Oracle, and Sybase. Performance measurements on the fully operational prototypes under the TPC-C benchmark show that the run-time overhead of the intrusion-resilience mechanism is between 6% and 13%.
  • Keywords
    authorisation; database management systems; error detection; DBMS; Oracle; PostgreSQL; Sybase; TPC-C benchmark; database management systems; erroneous transaction; error detection; intrusion detection; intrusion-resilient mechanism; malicious attacks; malicious transaction; Availability; Computer errors; Computer science; Database systems; File servers; Hardware; Humans; Information systems; Resilience; Transaction databases;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems and Networks, 2004 International Conference on
  • Print_ISBN
    0-7695-2052-9
  • Type

    conf

  • DOI
    10.1109/DSN.2004.1311914
  • Filename
    1311914