Recovering from Malicious Attacks in Workflow Systems
Workflow management systems (WFMS) coordinate execution of logically related multiple tasks in an organization. Such coordination is achieved through dependencies that are specified between the tasks of a workflow. Often times preventive measures are not enough and a workflow may be subjected to malicious attacks. Traditional workflow recovery mechanisms do not address how to recover from malicious attacks. Database survivability techniques do not work for workflow because tasks in a workflow have dependencies that are not present in traditional transaction processing systems. In this paper, we present an algorithm that shows how we can assess and repair the effects of damage caused by malicious tasks. Our algorithm focuses not only on restoring the consistency of data items by removing the effects of malicious tasks but also takes appropriate actions to ensure the satisfaction of task dependencies among all the committed tasks.
Unable to display preview. Download preview PDF.
- 2.Bernstein, P.A., Hadzilacos, V., Goodman, N.: Concurrency Control and Recovery in Database Systems. Addison-Wesley, Reading (1987)Google Scholar
- 3.Chrysanthis, P.: ACTA, A framework for modeling and reasoning aout extended transactions. PhD thesis, University of Massachusetts, Amherst, Massachusetts (1991)Google Scholar
- 4.Eder, J., Liebhart, W.: Workflow Recovery. In: Proceeding of Conference on Cooperative Information Systems, pp. 124–134 (1996)Google Scholar
- 5.Gore, M.M., Ghosh, R.K.: Recovery in Distributed Extended Long-lived Transaction Models. In: Proceedings of the 6th International Conference DataBase Systems for Advanced Applications, April 1999, pp. 313–320 (1999)Google Scholar
- 6.Kiepuszewski, B., Muhlberger, R., Orlowska, M.: Flowback: Providing backward recovery for workflow systems. In: Proceeding of the ACM SIGMOD International Conference on Management of Data, pp. 555–557 (1998)Google Scholar
- 8.Yu, M., Liu, P., Zang, W.: Multi-Version Attack Recovery for Workflow Systems. In: 19th Annual Computer Security Applications Conference, December 2003, pp. 142–151 (2003)Google Scholar