Addressing a Malicious Tampering Attack on the Default Isolation Level in DBMS

Abdullah Alhajri, Arshad Jhumka · 2023

There exists a plethora of online transaction processing (OLTP) applications, such as banking and inventory management. Database management systems (DBMS) use concurrency control mechanisms to manage OLTP transactions and their conflicts simultaneously. We introduce a DBMS attack, namely default isolation level manipulation (DILM), and investigate the security problem related to the malicious alteration of the default isolation level and suggest precautions and a technique to alleviate its effects. We assume an attacker with administrative privileges who can observe traffic and subsequently alter isolation levels, and we discuss the potential consequences of concurrency-related attacks. The algorithm is able to detect all the anomalies according to its objective function with a high accuracy rate.

Read the paper · More papers on PaperTik