DocumentCode
822704
Title
Recovery from malicious transactions
Author
Ammann, Paul ; Jajodia, Sushil ; Liu, Peng
Author_Institution
Center for Secure Inf. Syst., George Mason Univ., Fairfax, VA, USA
Volume
14
Issue
5
fYear
2002
Firstpage
1167
Lastpage
1185
Abstract
Preventive measures sometimes fail to deflect malicious attacks. We adopt an information warfare perspective, which assumes success by the attacker in achieving partial, but not complete, damage. In particular, we work in the database context and consider recovery from malicious but committed transactions. Traditional recovery mechanisms do not address this problem, except for complete rollbacks, which undo the work of benign transactions as well as malicious ones, and compensating transactions, whose utility depends on application semantics. Recovery is complicated by the presence of benign transactions that depend, directly or indirectly, on the malicious transactions. We present algorithms to restore only the damaged part of the database. We identify the information that needs to be maintained for such algorithms. The initial algorithms repair damage to quiescent databases; subsequent algorithms increase availability by allowing new transactions to execute concurrently with the repair process. Also, via a study of benchmarks, we show practical examples of how offline analysis can efficiently provide the necessary data to repair the damage of malicious transactions.
Keywords
data integrity; database management systems; security of data; software performance evaluation; system recovery; transaction processing; application semantics; benchmarks; benign transactions; complete rollbacks; data integrity; database; database security; information warfare; malicious transaction recovery; offline analysis; transaction processing; Air traffic control; Authorization; Banking; Credit cards; Data security; Database systems; Intrusion detection; Logistics; Protection; Transaction databases;
fLanguage
English
Journal_Title
Knowledge and Data Engineering, IEEE Transactions on
Publisher
ieee
ISSN
1041-4347
Type
jour
DOI
10.1109/TKDE.2002.1033782
Filename
1033782
Link To Document