DocumentCode
3147905
Title
A portable implementation framework for intrusion-resilient database management systems
Author
Smirnov, Alexey ; Chiueh, Tzi-cker
Author_Institution
Dept. of Comput. Sci., SUNY, Stony Brook, NY, USA
fYear
2004
fDate
28 June-1 July 2004
Firstpage
443
Lastpage
452
Abstract
An intrusion-resilient database management system is the one that is capable of restoring its consistency after being compromised by a malicious attack or a human error. More specifically, an intrusion-resilient mechanism helps to quickly repair a database by ifying the damage caused by malicious or erroneous transactions, while preserving the effects of unaffected legitimate transactions that take place between intrusions/errors and their detection. The goal of this project is to develop a portable implementation framework that can augment a commercial database management system with intrusion resilience without requiring any modifications to its internals. The intrusion resilience mechanism described in this paper significantly improves the availability of modern DBMSs by facilitating and sometimes even automating the post-intrusion damage repair process. In addition, it can be embodied in a reusable implementation framework, whose portability is demonstrated by its successful application to three different DBMSs: PostgreSQL, Oracle, and Sybase. Performance measurements on the fully operational prototypes under the TPC-C benchmark show that the run-time overhead of the intrusion-resilience mechanism is between 6% and 13%.
Keywords
authorisation; database management systems; error detection; DBMS; Oracle; PostgreSQL; Sybase; TPC-C benchmark; database management systems; erroneous transaction; error detection; intrusion detection; intrusion-resilient mechanism; malicious attacks; malicious transaction; Availability; Computer errors; Computer science; Database systems; File servers; Hardware; Humans; Information systems; Resilience; Transaction databases;
fLanguage
English
Publisher
ieee
Conference_Titel
Dependable Systems and Networks, 2004 International Conference on
Print_ISBN
0-7695-2052-9
Type
conf
DOI
10.1109/DSN.2004.1311914
Filename
1311914
Link To Document