loading...
Database Isolation and Filtering against Data Corruption Attacks
Miami Beach, Florida, USA December 10-December 14
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ACSAC.2007.18Twenty-Third Annual Computer Security ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Various attacks (e.g., SQL injections) may corrupt data items in the database systems, which decreases the integrity level of the database. Intrusion detections systems are be- coming more and more sophisticated to detect such attacks. However, more advanced detection techniques require more complicated analyses, e.g, sequential analysis, which incurs detection latency. If we have an intrusion detection system as a filter for all system inputs, we will introduce a uniform processing latency to all transactions of the database sys- tem. In this paper, we propose to use a "unsafe zone" to iso- late user's SQL queries from a "safe zone" of the database. In the unsafe zone, we use polyinstantiations and flags for the records to provide an immediate but different view from that of the safe zone to the user. Such isolation has negligi- ble processing latency from the user's view, while it can sig- nificantly improve the integrity level of the whole database system and reduce the recovery costs. Our techniques pro- vide different integrity levels within different zones. Both our analytical and experimental results confirm the effec- tiveness of our isolation techniques against data corruption attacks to the databases. Our techniques can be applied to database systems to provide multizone isolations with dif- ferent levels of QoS.
Citation:
Meng Yu, Wanyu Zang, Peng Liu, "Database Isolation and Filtering against Data Corruption Attacks," acsac, pp.97-106, Twenty-Third Annual Computer Security Applications Conference (ACSAC 2007), 2007
Usage of this product signifies your acceptance of the Terms of Use.