loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
1997 IEEE Symposium on Security and Privacy
Surviving information warfare attacks on databases
Oakland, CA
May 04-May 07
ISBN: 0-8186-7828-3
P. Ammann, Center for Secure Inf. Syst., George Mason Univ., Fairfax, VA, USA
S. Jajodia, Center for Secure Inf. Syst., George Mason Univ., Fairfax, VA, USA
C.D. McCollum, Center for Secure Inf. Syst., George Mason Univ., Fairfax, VA, USA
B.T. Blaustein, Center for Secure Inf. Syst., George Mason Univ., Fairfax, VA, USA
Abstract: We consider the problem of surviving information warfare attacks on databases. We adopt a fault tolerance approach to the different phases of an attack. To maintain precise information about the attack, we mark data to reflect the severity of detected damage as well as the degree to which the damaged data has been repaired. In the case of partially repaired data, integrity constraints might be violated, but data is nonetheless available to support mission objectives. We define a notion of consistency suitable for databases in which some information is known to be damaged, and other information is known to be only partially repaired. We present a protocol for normal transactions with respect to the damage markings and show that consistency preserving normal transactions maintain database consistency in the presence of damage. We present an algorithm for taking consistent snapshots of databases under attack. The snapshot algorithm has the virtue of not interfering with countermeasure transactions.
Index Terms:
security of data; information warfare attack survival; databases; fault tolerance approach; damaged data; partially repaired data; integrity constraints; database consistency; protocol; snapshot algorithm; damage markings; consistency preserving normal transactions; countermeasure transactions; data security
Citation:
P. Ammann, S. Jajodia, C.D. McCollum, B.T. Blaustein, "Surviving information warfare attacks on databases," sp, pp.0164, 1997 IEEE Symposium on Security and Privacy, 1997
Usage of this product signifies your acceptance of the Terms of Use.