Verity: Blockchain Based Framework to Detect Insider Attacks in DBMS

2020 IEEE International Conference on Blockchain (Blockchain)(2020)

引用 0|浏览17
暂无评分
摘要
Integrity and security of databases are maintained with access control policies and firewalls. However, insider attacks - where someone with administrative privileges tampers with the data - pose a unique challenge. In this paper, we propose Verity - first of a kind system to the best of our knowledge - to detect insider attacks in databases. Verity serves as a dataless framework by which any blockchain network can be used to store fixed-length fingerprints of tuples from any SQL database, without complete migration of the data. Verity uses a formalism for intercepting SQL queries and their results to check the respective tuples' integrity using the fingerprints stored on the blockchain, and detect an insider attack. We have implemented our technique using Hyperledger Fabric, and SQLite database. Using TPC-H data and CRUD (Create, Read, Update, Delete) SQL queries of varying complexity and nestings, our experiments demonstrate that any overhead of tuple integrity checking remains constant per tuple in a query's results, and scales linearly.
更多
查看译文
关键词
Blockchain,database,insider attacks,security
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要