Intrusion recovery for database-backed web applications

Intrusion recovery for database-backed web applications
复制标题

数据库支持的 Web 应用程序的入侵恢复

DOI:
10.1145/2043556.2043567
复制
发表时间:
2011
期刊:
Proceedings of the Twenty-Third ACM Symposium on Operating Systems Principles
影响因子:
--
通讯作者:
Nickolai Zeldovich
Nickolai Zeldovich
中科院分区:
--
文献类型:
--
作者:
Ramesh Chandra;Taesoo Kim;Meelap Shah;Neha Narula;Nickolai Zeldovich

文献摘要

被引文献

相似文献

Warp是一个帮助Web应用程序的用户和管理员从入侵(如SQL注入,跨站脚本和点击劫持攻击)中恢复的系统,同时保留合法的用户更改。通过将部分数据库回滚到攻击前的版本,并重播后续的合法操作,对入侵进行翘曲修复。Warp允许管理员追溯修补安全漏洞-即,将新的安全补丁应用到过去的执行中---从入侵中恢复,而不需要管理员跟踪甚至检测攻击。Warp的时间旅行数据库允许数据库行的细粒度回滚,并使修复与Web应用程序的正常操作并发进行。最后,Warp在浏览器的DOM级别捕获并重放用户输入,以从涉及用户浏览器的攻击中恢复。对于运行MediaWiki的Web服务器,Warp不需要更改应用程序源代码,就可以以最少的用户输入从一系列常见的Web应用程序漏洞中恢复,而吞吐量的成本为24- 27%,存储空间为2- 3.2 GB/天。
Warp is a system that helps users and administrators of web applications recover from intrusions such as SQL injection, cross-site scripting, and clickjacking attacks, while preserving legitimate user changes. Warp repairs from an intrusion by rolling back parts of the database to a version before the attack, and replaying subsequent legitimate actions. Warp allows administrators to retroactively patch security vulnerabilities---i.e., apply new security patches to past executions---to recover from intrusions without requiring the administrator to track down or even detect attacks. Warp's time-travel database allows fine-grained rollback of database rows, and enables repair to proceed concurrently with normal operation of a web application. Finally, Warp captures and replays user input at the level of a browser's DOM, to recover from attacks that involve a user's browser. For a web server running MediaWiki, Warp requires no application source code changes to recover from a range of common web application vulnerabilities with minimal user input at a cost of 24--27% in throughput and 2--3.2 GB/day in storage.