Self-healing workflow systems under attacks

Self-healing workflow systems under attacks
复制标题

受到攻击的自我修复工作流程系统

DOI:
10.1109/icdcs.2004.1281607
复制
发表时间:
2004
期刊:
24th International Conference on Distributed Computing Systems, 2004. Proceedings.
影响因子:
--
通讯作者:
Wanyu Zang
Wanyu Zang
中科院分区:
--
文献类型:
--
作者:
Meng Yu;Peng Liu;Wanyu Zang

文献摘要

被引文献

相似文献

工作流系统在日常业务处理中得到了广泛的应用。由于漏洞无法从工作流管理系统中完全消除,成功的攻击总是会发生,并可能将恶意任务或错误数据注入工作流系统。引用不正确的数据会进一步破坏系统中的更多数据对象,这包括系统的完整性级别。现有的访问控制、入侵检测和检查点等防御机制无法有效解决这一问题。在本文中,我们提出了一个实用的解决方案,在线攻击恢复的工作流。恢复系统发现入侵检测系统报告的恶意任务造成的所有损害,并根据工作流任务之间的数据和控制依赖关系自动修复损害。我们分析了我们的攻击恢复系统的行为的基础上的连续时间马尔可夫链模型。分析结果表明,只要系统参数设计合理,系统是实用的。
Workflow systems are popular in daily business processing. Since vulnerability cannot be totally removed from a workflow management system, successful attacks always happen and may inject malicious tasks or incorrect data into the workflow system. Referring to the incorrect data further corrupt more data objects in the system, which comprises the integrity level of the system. This problem cannot be efficiently solved by existing defense mechanisms, such as access control, intrusion detection, and checkpoints. In this paper, we propose a practical solution for online attack recovery of workflows. The recovery system discovers all damages caused by the malicious tasks that the intrusion detection system reports and automatically repairs the damages based on data and control dependencies among workflow tasks. We analyze the behaviors of our attack recovery system based on the continuous time Markov chain model. The analytical results demonstrate that our system is practical when the parameters of the system are reasonably designed.