Investigating the Effect of an Attack on a Distributed Database
Rami Samara, Brajendra Panda · 2006
After an attack on a database system, evaluation of damage must be performed as soon the attack is identified. Otherwise, the initial damage will spread to other parts of the database via valid transactions, consequently resulting in denial-of-service. Damage assessment in a distributed database system is a complicated task due to intricate transaction relationships among distributed sites. In these systems, when any sub-transaction reads a damaged data at any site, the entire transaction of which the sub-transaction is a part, is considered affected by the damage. Hence, the data items updated by that transaction irrespective of sites are also considered damaged. This research focuses on damage assessment procedure for distributed database systems and uses a two-pass algorithm to obtain the final list of affected data items. The advantages of this method are: (1) the process is fully distributed in the sense that every site will execute the same algorithm, (2) the amount of data to be exchanged between the sites is minimized to the list of affected items at each site instead of the entire log, and (3) the local damage assessors can be executed in parallel at their respective sites. valid transactions update data items after reading a damaged data item. As more and more data items become affected, the spread of damage becomes even faster. Unless assessed and recovered quickly, the effect will be far reaching. Like any digital investigation process, the logs contain valuable information and need to be checked thoroughly for the effect of the attack. This must be done swiftly and accurately so that the system can be made operational as soon as possible and that the system is completely free of any damage. In this paper we present a model to assess the damage in a distributed database. We have developed an algorithm that would be executed in two phases; during the first phase, local logs at sites where a malicious transaction is executed will be examined and during the second phase, correlation among logs at various sites will be made to see which data items are affected. In section 2, we briefly describe some related work performed in this area. Our model is presented in section 3 and the damage assessment method is discussed in section 4. Section 5 concludes the paper.