Kyriacos E. Pavlou

dblp:72/2214 · DBLP profile ↗
← Back
7ranked-venue papers
6as first author
0since 2021 · last 2013
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Databases, data management, data science and information retrieval · 5 · 5 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Digital forensics and information hiding · 94% Cryptographic primitives and cryptanalysis · 6%
Computer architecture, parallel and distributed computing, and storage systems
4 papers
Storage systems · 100%

Topics — the 6 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Digital forensics and information hiding › digital forensics
database forensics
0.552013
Generalizing database forensics · ACM Trans. Database Syst. 2013
The Tiled Bitmap Forensic Analysis Algorithm · IEEE Trans. Knowl. Data Eng. 2010
Forensic analysis of database tampering · ACM Trans. Database Syst. 2008
Digital forensics and information hiding › content authentication
tamper detection
0.332012
DRAGOON: An Information Accountability System for High-Performance Databases · ICDE 2012
The Tiled Bitmap Forensic Analysis Algorithm · IEEE Trans. Knowl. Data Eng. 2010
Forensic analysis of database tampering · ACM Trans. Database Syst. 2008
Storage systems
storage reliability
0.342013
Generalizing database forensics · ACM Trans. Database Syst. 2013
Forensic analysis of database tampering · ACM Trans. Database Syst. 2008
DRAGOON: An Information Accountability System for High-Performance Databases · ICDE 2012
Digital forensics and information hiding › digital forensics
forensic analysis
0.212013
Generalizing database forensics · ACM Trans. Database Syst. 2013
Storage systems › storage reliability
corruption detection
0.212013
Generalizing database forensics · ACM Trans. Database Syst. 2013
Cryptographic primitives and cryptanalysis
hash functions
0.112006
Forensic analysis of database tampering · SIGMOD Conference 2006

Methods — techniques the papers use, named apart from their topics

page-based partitioning · 0.3attribute-based partitioning · 0.3cryptographic hashing · 0.3tiled bitmap · 0.2monochromatic · 0.2forensic analysis algorithms · 0.2RGBY · 0.23d · 0.2cryptographic hash functions · 0.1cryptographic hash function · 0.1
YearPublicationVenuePosition
2013 Generalizing database forensics
abstract
In this article we present refinements on previously proposed approaches to forensic analysis of database tampering. We significantly generalize the basic structure of these algorithms to admit new characterizations of the “where” axis of the corruption diagram. Specifically, we introduce page-based partitioning as well as attribute-based partitioning along with their associated corruption diagrams. We compare the structure of all the forensic analysis algorithms and discuss the various design choices available with respect to forensic analysis. We characterize the forensic cost of the newly introduced algorithms, compare their forensic cost, and give our recommendations. We then introduce a comprehensive taxonomy of the types of possible corruption events, along with an associated forensic analysis protocol that consolidates all extant forensic algorithms and the corresponding type(s) of corruption events they detect. The result is a generalization of these algorithms and an overarching characterization of the process of database forensic analysis, thus providing a context within the overall operation of a DBMS for all existing forensic analysis algorithms.
Kyriacos E. Pavlou, Richard T. Snodgrass
ACM Trans. Database Syst.1
2012 DRAGOON: An Information Accountability System for High-Performance Databases
abstract
Regulations and societal expectations have recently emphasized the need to mediate access to valuable databases, even access by insiders. Fraud occurs when a person, often an insider, tries to hide illegal activity. Companies would like to be assured that such tampering has not occurred, or if it does, that it will be quickly discovered and used to identify the perpetrator. At one end of the compliance spectrum lies the approach of restricting access to information and on the other that of information accountability. We focus on effecting information accountability of data stored in high-performance databases. The demonstrated work ensures appropriate use and thus end-to-end accountability of database information via a continuous assurance technology based on cryptographic hashing techniques. A prototype tamper detection and forensic analysis system named DRAGOON was designed and implemented to determine when tampering(s) occurred and what data were tampered with. DRAGOON is scalable, customizable, and intuitive. This work will show that information accountability is a viable alternative to information restriction for ensuring the correct storage, use, and maintenance of databases on extant DBMSes.
Kyriacos E. Pavlou, Richard T. Snodgrass
ICDE1
2012 Temporal Implications of Database Information Accountability
abstract
Information restriction controls access and renders records immutable, information accountability requires data transparency to easily and efficiently determine when a particular use is appropriate. Information accountability in the context of relational databases is associated with time in a surprising number of ways, as is summarized in this paper. Notarization and validation of a database exploit the temporal semantics of a transaction-time database. A corruption can be associated with multiple times. Forensic analysis determines the when: bounds on the corruption time, and the where: also specified in terms of time. These bounds are depicted in a two-dimensional corruption diagram, with both axes denoting time. The various kinds of corruption events are defined in terms of time. A parameter termed the regret interval has significant security and performance implications. This paper emphasizes the deep connections between time and the definition, detection, forensic analysis, and characterized extent of a database corruption within the context of information accountability.
Kyriacos E. Pavlou, Richard T. Snodgrass
TIME1
2010 The Tiled Bitmap Forensic Analysis Algorithm
abstract
Tampering of a database can be detected through the use of cryptographically strong hash functions. Subsequently, applied forensic analysis algorithms can help determine when, what, and perhaps ultimately who and why. This paper presents a novel forensic analysis algorithm, the tiled Bitmap algorithm, which is more efficient than prior forensic analysis algorithms. It introduces the notion of a candidate set (all possible locations of detected tampering(s)) and provides a complete characterization of the candidate set and its cardinality. An optimal algorithm for computing the candidate set is also presented. Finally, the implementation of the tiled Bitmap algorithm is discussed, along with a comparison to other forensic algorithms in terms of space/time complexity and cost. An example of candidate set generation and proofs of the theorems and lemmata and of algorithm correctness can be found in the appendix, which can be found on the Computer Society Digital Library at http://doi.ieeecomputersociety.org/10.1109/TKDE.2009.121.
Kyriacos E. Pavlou, Richard T. Snodgrass
IEEE Trans. Knowl. Data Eng.1
2008 Forensic analysis of database tampering
abstract
Regulations and societal expectations have recently expressed the need to mediate access to valuable databases, even by insiders. One approach is tamper detection via cryptographic hashing. This article shows how to determine when the tampering occurred, what data was tampered with, and perhaps, ultimately, who did the tampering, via forensic analysis. We present four successively more sophisticated forensic analysis algorithms: the Monochromatic, RGBY, Tiled Bitmap, and a3D algorithms, and characterize their “forensic cost” under worst-case, best-case, and average-case assumptions on the distribution of corruption sites. A lower bound on forensic cost is derived, with RGBY and a3D being shown optimal for a large number of corruptions. We also provide validated cost formulæ for these algorithms and recommendations for the circumstances in which each algorithm is indicated.
Kyriacos E. Pavlou, Richard T. Snodgrass
ACM Trans. Database Syst.1
2006 Forensic analysis of database tampering
abstract
Mechanisms now exist that detect tampering of a database, through the use of cryptographically-strong hash functions. This paper addresses the next problem, that of determining who, when, and what, by providing a systematic means of performing forensic analysis after such tampering has been uncovered. We introduce a schematic representation termed a "corruption diagram" that aids in intrusion investigation. We use these diagrams to fully analyze the original proposal, that of a linked sequence of hash values. We examine the various kinds of intrusions that are possible, including retroactive, introactive, backdating, and postdating intrusions. We then introduce successively more sophisticated forensic analysis algorithms: the monochromatic, RGB, and polychromatic algorithms, and characterize the "forensic strength" of these algorithms. We show how forensic analysis can efficiently extract a good deal of information concerning a corruption event.
Kyriacos E. Pavlou, Richard T. Snodgrass
SIGMOD Conference1
2005 Collaboration with DiamondTouch
Stephen G. Kobourov, Kyriacos E. Pavlou, Justin Cappos, Michael Stepp, Mark Miles, Amanda Wixted
INTERACT2