| A data damage tracking quarantine and recovery (DTQR) scheme for mission-critical database systems |
| Full text |
Pdf
(1.02 MB)
|
| Source
|
Extending Database Technology; Vol. 360
archive
Proceedings of the 12th International Conference on Extending Database Technology: Advances in Database Technology
table of contents
Saint Petersburg, Russia
SESSION: Research sessions: Workflow techniques
table of contents
Pages 720-731
Year of Publication: 2009
ISBN:978-1-60558-422-5
|
|
Authors
|
|
Kun Bai
|
The Pennsylvania State University, University Park, PA
|
|
Peng Liu
|
The Pennsylvania State University, University Park, PA
|
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 31, Downloads (12 Months): 122, Citation Count: 0
|
|
|
ABSTRACT
Database security research aims to protect a database from unintended activities, such as authenticated misuse, malicious attacks. In recent years, surviving DBMS from an attack is becoming even more crucial because networks have become more open and the increasingly critical role that database servers are playing nowadays. Unlike the traditional database failure/attack recovery mechanisms, in this paper, we propose a light-weight dynamic Data Damage Tracking, Quarantine, and Recovery (DTQR) solution. We built the DTQR scheme into the kernel of PostgreSQL. We comprehensively study this approach from a few aspects (e.g., system overhead, impact of the intrusion detection system), and the experimental results demonstrated that our DTQR can sustain an excellent data service while healing the database server when it is under a malicious attack.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
|
| |
2
|
|
| |
3
|
|
| |
4
|
|
| |
5
|
|
| |
6
|
|
| |
7
|
CERT. Cert advisory ca-2003-04 ms-sql server worm. http://www.cert.org/advisories/CA-2003-04.html, January, 25 2003.
|
| |
8
|
|
 |
9
|
|
| |
10
|
|
| |
11
|
|
| |
12
|
|
| |
13
|
|
| |
14
|
|
 |
15
|
|
| |
16
|
|
 |
17
|
|
| |
18
|
OWASP. Owasp top ten most critical web application security vulnerabilities. http://www.owasp.org/documentation/topten.html, January, 27 2004.
|
| |
19
|
|
| |
20
|
|
| |
21
|
Postgresql. http://www.postgresql.org/.
|
| |
22
|
|
| |
23
|
F. Valeur, D. Mutz, and G. Vigna. A learning-based approach to the detection of sql attacks. In Conference on Detection of Intrusions and Malware Vulnerability Assessment (DIMVA), pages 123--140, 2005.
|
|