论文标题

基于链接遍历的查询处理(扩展版本)中安全漏洞的前瞻性分析(扩展版)

A Prospective Analysis of Security Vulnerabilities within Link Traversal-Based Query Processing (Extended Version)

论文作者

Taelman, Ruben, Verborgh, Ruben

论文摘要

围绕大数据驱动平台的社会和经济后果增加了对分散解决方案的呼吁。但是,在更分散的环境中检索和查询数据需要根本不同的方法,其属性尚未得到充分理解。基于链接遍历的查询处理(LTQP)是一种通过分散数据网络查询的技术,在该技术中,客户端查询引擎通过遍历文档之间的链接来发现数据。由于由于其非中央控制性质,分散的环境可能不安全,因此客户端LTQP查询引擎需要抵抗针对查询引擎的主机机器或查询启动器的个人数据的安全威胁。因此,我们对LTQP的潜在安全漏洞进行了分析。本文概述了相关域中的安全威胁,这些威胁被用作识别10个LTQP安全威胁的灵感。解释了每个威胁,以及一个例子,并提出了一种或多种缓解途径。最后,我们对LTQP查询引擎开发人员和数据出版商的一些具体建议作为减轻其中一些问题的第一步。通过这项工作,我们开始填写未知数,以在分散环境中进行查询。除了将来的安全工作外,还需要更广泛的研究来揭示缺少真正的权力下放的构件。

The societal and economical consequences surrounding Big Data-driven platforms have increased the call for decentralized solutions. However, retrieving and querying data in more decentralized environments requires fundamentally different approaches, whose properties are not yet well understood. Link Traversal-based Query Processing (LTQP) is a technique for querying over decentralized data networks, in which a client-side query engine discovers data by traversing links between documents. Since decentralized environments are potentially unsafe due to their non-centrally controlled nature, there is a need for client-side LTQP query engines to be resistant against security threats aimed at the query engine's host machine or the query initiator's personal data. As such, we have performed an analysis of potential security vulnerabilities of LTQP. This article provides an overview of security threats in related domains, which are used as inspiration for the identification of 10 LTQP security threats. Each threat is explained, together with an example, and one or more avenues for mitigations are proposed. We conclude with several concrete recommendations for LTQP query engine developers and data publishers as a first step to mitigate some of these issues. With this work, we start filling the unknowns for enabling querying over decentralized environments. Aside from future work on security, wider research is needed to uncover missing building blocks for enabling true decentralization.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源