A Framework to Reverse Engineer Database Memory by Abstracting Memory Areas

A Framework to Reverse Engineer Database Memory by Abstracting Memory Areas
复制标题

一种通过抽象内存区域来逆向工程数据库内存的框架

DOI:
10.1007/978-3-030-59003-1_20
复制
发表时间:
2020
期刊:
DEXA 2020: Database and Expert Systems Applications
影响因子:
--
通讯作者:
Rasin, Alexander
Rasin, Alexander
中科院分区:
--
文献类型:
--
作者:
Wagner, James;Rasin, Alexander

文献摘要

参考文献

被引文献

相似文献

操作系统(OS)中RAM的内容是恶意软件检测或系统性能分析的关键证据来源。数字取证专注于重建OS RAM结构,以在运行时检测恶意软件模式。在持续的军备竞赛中,这些RAM重建方法必须针对它们试图检测的攻击而设计。即使数据库管理系统(DBMS)是集体负责存储和处理组织中的大部分数据,内存重建的等效问题还没有被认为是DBMS管理的RAM。在本文中,我们提出并评估了一个系统的方法来逆向工程数据结构和访问模式在DBMS RAM。我们描述了一种检测和跟踪DBMS中任何RAM区域的方法,而不是为特定场景开发解决方案。我们评估我们的方法与四个最常见的RAM领域,在知名的DBMS,本文介绍了设计的每个区域特定的查询工作量和过程中捕获和量化该地区在运行时。我们进一步评估我们的方法,通过观察内置的DBMS加密存在的RAM数据流。我们提出了一个可用的DBMS加密机制,其相对的优点和缺点的概述,然后说明的四个内存区域的实际影响。
The contents of RAM in an operating system (OS) are a critical source of evidence for malware detection or system performance profiling. Digital forensics focused on reconstructing OS RAM structures to detect malware patterns at runtime. In an ongoing arms race, these RAM reconstruction approaches must be designed for the attack they are trying to detect. Even though database management systems (DBMS) are collectively responsible for storing and processing most data in organizations, the equivalent problem of memory reconstruction has not been considered for DBMS-managed RAM.In this paper, we propose and evaluate a systematic approach to reverse engineer data structures and access patterns in DBMS RAM. Rather than develop a solution for specific scenarios, we describe an approach to detect and track any RAM area in a DBMS. We evaluate our approach with the four most common RAM areas in well-known DBMSes; this paper describes the design of each area-specific query workload and the process to capture and quantify that area at runtime. We further evaluate our approach by observing the RAM data flow in presence of built-in DBMS encryption. We present an overview of available DBMS encryption mechanisms, their relative advantages and disadvantages, and then illustrate the practical implications for the four memory areas.
数据库系统取证分析中的隐私威胁
DOI: 10.1145/1247480.1247492
发表时间: 2007
期刊: Digit. Investig.
影响因子: --
作者:
Patrick Stahlberg;G. Miklau;B. Levine
通讯作者: B. Levine
DOI: --
发表时间: 2016
期刊: SPACE
影响因子: 0.3
作者:
Jian Liu;Sihem Mesnager;Lusheng Chen
通讯作者: Lusheng Chen
使用 DBCarver 进行数据库取证分析
DOI: --
发表时间: 2017
期刊: 8th Biennial Conference on Innovative Data Systems Research
影响因子: --
作者:
Wagner, James;Rasin, Alexander;Malik, Tanu;Heart, Karen;Jehle, Hugo;Grier, Jonathan
通讯作者: Grier, Jonathan
DOI: 10.1145/2046660.2046682
发表时间: 2011-10
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
K. Lauter;M. Naehrig;V. Vaikuntanathan
通讯作者: K. Lauter;M. Naehrig;V. Vaikuntanathan
关于使用 CryptDB 保护 Web 应用程序安全的困难
DOI: --
发表时间: 2014
期刊: 2014 IEEE Fourth International Conference on Big Data and Cloud Computing
影响因子: --
作者:
Ihsan Haluk Akin;B. Sunar
通讯作者: B. Sunar