EDBT 2026 Demo / reviewers in the wild / expert
Kyriacos E. Pavlou
dblp:72/2214
· DBLP profile ↗
7ranked-venue papers
6as first author
0since 2021 · last 2013
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 5 · 5 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
5 papers |
Digital forensics and information hiding · 94% Cryptographic primitives and cryptanalysis · 6% | |
| Computer architecture, parallel and distributed computing, and storage systems
4 papers |
Storage systems · 100% |
Topics — the 6 heaviest of 6, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Digital forensics and information hiding › digital forensics
database forensics |
0.5 | 5 | 2013 | Generalizing database forensics · ACM Trans. Database Syst. 2013 The Tiled Bitmap Forensic Analysis Algorithm · IEEE Trans. Knowl. Data Eng. 2010 Forensic analysis of database tampering · ACM Trans. Database Syst. 2008 |
Digital forensics and information hiding › content authentication
tamper detection |
0.3 | 3 | 2012 | DRAGOON: An Information Accountability System for High-Performance Databases · ICDE 2012 The Tiled Bitmap Forensic Analysis Algorithm · IEEE Trans. Knowl. Data Eng. 2010 Forensic analysis of database tampering · ACM Trans. Database Syst. 2008 |
Storage systems
storage reliability |
0.3 | 4 | 2013 | Generalizing database forensics · ACM Trans. Database Syst. 2013 Forensic analysis of database tampering · ACM Trans. Database Syst. 2008 DRAGOON: An Information Accountability System for High-Performance Databases · ICDE 2012 |
Digital forensics and information hiding › digital forensics
forensic analysis |
0.2 | 1 | 2013 | Generalizing database forensics · ACM Trans. Database Syst. 2013 |
Storage systems › storage reliability
corruption detection |
0.2 | 1 | 2013 | Generalizing database forensics · ACM Trans. Database Syst. 2013 |
Cryptographic primitives and cryptanalysis
hash functions |
0.1 | 1 | 2006 | Forensic analysis of database tampering · SIGMOD Conference 2006 |
Methods — techniques the papers use, named apart from their topics
page-based partitioning · 0.3attribute-based partitioning · 0.3cryptographic hashing · 0.3tiled bitmap · 0.2monochromatic · 0.2forensic analysis algorithms · 0.2RGBY · 0.23d · 0.2cryptographic hash functions · 0.1cryptographic hash function · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2013 | Generalizing database forensicsabstractIn this article we present refinements on previously proposed approaches to forensic analysis of database tampering. We significantly generalize the basic structure of these algorithms to admit new characterizations of the “where” axis of the corruption diagram. Specifically, we introduce page-based partitioning as well as attribute-based partitioning along with their associated corruption diagrams. We compare the structure of all the forensic analysis algorithms and discuss the various design choices available with respect to forensic analysis. We characterize the forensic cost of the newly introduced algorithms, compare their forensic cost, and give our recommendations. We then introduce a comprehensive taxonomy of the types of possible corruption events, along with an associated forensic analysis protocol that consolidates all extant forensic algorithms and the corresponding type(s) of corruption events they detect. The result is a generalization of these algorithms and an overarching characterization of the process of database forensic analysis, thus providing a context within the overall operation of a DBMS for all existing forensic analysis algorithms. Kyriacos E. Pavlou, Richard T. Snodgrass |
ACM Trans. Database Syst. | 1 |
| 2012 | DRAGOON: An Information Accountability System for High-Performance DatabasesabstractRegulations and societal expectations have recently emphasized the need to mediate access to valuable databases, even access by insiders. Fraud occurs when a person, often an insider, tries to hide illegal activity. Companies would like to be assured that such tampering has not occurred, or if it does, that it will be quickly discovered and used to identify the perpetrator. At one end of the compliance spectrum lies the approach of restricting access to information and on the other that of information accountability. We focus on effecting information accountability of data stored in high-performance databases. The demonstrated work ensures appropriate use and thus end-to-end accountability of database information via a continuous assurance technology based on cryptographic hashing techniques. A prototype tamper detection and forensic analysis system named DRAGOON was designed and implemented to determine when tampering(s) occurred and what data were tampered with. DRAGOON is scalable, customizable, and intuitive. This work will show that information accountability is a viable alternative to information restriction for ensuring the correct storage, use, and maintenance of databases on extant DBMSes. Kyriacos E. Pavlou, Richard T. Snodgrass |
ICDE | 1 |
| 2012 | Temporal Implications of Database Information AccountabilityabstractInformation restriction controls access and renders records immutable, information accountability requires data transparency to easily and efficiently determine when a particular use is appropriate. Information accountability in the context of relational databases is associated with time in a surprising number of ways, as is summarized in this paper. Notarization and validation of a database exploit the temporal semantics of a transaction-time database. A corruption can be associated with multiple times. Forensic analysis determines the when: bounds on the corruption time, and the where: also specified in terms of time. These bounds are depicted in a two-dimensional corruption diagram, with both axes denoting time. The various kinds of corruption events are defined in terms of time. A parameter termed the regret interval has significant security and performance implications. This paper emphasizes the deep connections between time and the definition, detection, forensic analysis, and characterized extent of a database corruption within the context of information accountability. Kyriacos E. Pavlou, Richard T. Snodgrass |
TIME | 1 |
| 2010 | The Tiled Bitmap Forensic Analysis AlgorithmabstractTampering of a database can be detected through the use of cryptographically strong hash functions. Subsequently, applied forensic analysis algorithms can help determine when, what, and perhaps ultimately who and why. This paper presents a novel forensic analysis algorithm, the tiled Bitmap algorithm, which is more efficient than prior forensic analysis algorithms. It introduces the notion of a candidate set (all possible locations of detected tampering(s)) and provides a complete characterization of the candidate set and its cardinality. An optimal algorithm for computing the candidate set is also presented. Finally, the implementation of the tiled Bitmap algorithm is discussed, along with a comparison to other forensic algorithms in terms of space/time complexity and cost. An example of candidate set generation and proofs of the theorems and lemmata and of algorithm correctness can be found in the appendix, which can be found on the Computer Society Digital Library at http://doi.ieeecomputersociety.org/10.1109/TKDE.2009.121. Kyriacos E. Pavlou, Richard T. Snodgrass |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2008 | Forensic analysis of database tamperingabstractRegulations and societal expectations have recently expressed the need to mediate access to valuable databases, even by insiders. One approach is tamper detection via cryptographic hashing. This article shows how to determine when the tampering occurred, what data was tampered with, and perhaps, ultimately, who did the tampering, via forensic analysis. We present four successively more sophisticated forensic analysis algorithms: the Monochromatic, RGBY, Tiled Bitmap, and a3D algorithms, and characterize their “forensic cost” under worst-case, best-case, and average-case assumptions on the distribution of corruption sites. A lower bound on forensic cost is derived, with RGBY and a3D being shown optimal for a large number of corruptions. We also provide validated cost formulæ for these algorithms and recommendations for the circumstances in which each algorithm is indicated. Kyriacos E. Pavlou, Richard T. Snodgrass |
ACM Trans. Database Syst. | 1 |
| 2006 | Forensic analysis of database tamperingabstractMechanisms now exist that detect tampering of a database, through the use of cryptographically-strong hash functions. This paper addresses the next problem, that of determining who, when, and what, by providing a systematic means of performing forensic analysis after such tampering has been uncovered. We introduce a schematic representation termed a "corruption diagram" that aids in intrusion investigation. We use these diagrams to fully analyze the original proposal, that of a linked sequence of hash values. We examine the various kinds of intrusions that are possible, including retroactive, introactive, backdating, and postdating intrusions. We then introduce successively more sophisticated forensic analysis algorithms: the monochromatic, RGB, and polychromatic algorithms, and characterize the "forensic strength" of these algorithms. We show how forensic analysis can efficiently extract a good deal of information concerning a corruption event. Kyriacos E. Pavlou, Richard T. Snodgrass |
SIGMOD Conference | 1 |
| 2005 | Collaboration with DiamondTouch
Stephen G. Kobourov, Kyriacos E. Pavlou, Justin Cappos, Michael Stepp, Mark Miles, Amanda Wixted |
INTERACT | 2 |