BigFoot: Exploiting and Mitigating Leakage in Encrypted Write-Ahead Logs

11/17/2021
by   Jialing Pei, et al.
0

Modern databases and data-warehousing systems separate query processing and durable storage. Storage systems have idiosyncratic bugs and security vulnerabilities, thus attacks that compromise only storage are a realistic threat. In this paper, we show that encryption alone is not sufficient to protect databases from compromised storage. Using MongoDB WiredTiger as a concrete example, we demonstrate that sizes of encrypted writes to a durable write-ahead log can reveal sensitive information about the inputs and activities of MongoDB applications. We then design, implement, and evaluate BigFoot, a WAL modification that mitigates size leakage.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/07/2018

Pushing the Limits of Encrypted Databases with Secure Hardware

Encrypted databases have been studied for more than 10 years and are qui...
research
04/11/2019

Information Leakage in Encrypted Deduplication via Frequency Analysis: Attacks and Defenses

Encrypted deduplication combines encryption and deduplication to simulta...
research
09/25/2019

Privacy-preserving Searchable Databases with Controllable Leakage

Searchable Encryption (SE) is a technique that allows Cloud Service Prov...
research
02/12/2020

EncDBDB: Searchable Encrypted, Fast, Compressed, In-Memory Database using Enclaves

Data confidentiality is an important requirement for clients when outsou...
research
12/04/2018

Exploiting Data Sensitivity on Partitioned Data

Several researchers have proposed solutions for secure data outsourcing ...
research
02/07/2022

Private Read Update Write (PRUW) with Storage Constrained Databases

We investigate the problem of private read update write (PRUW) in relati...
research
09/10/2009

Sparsity and `Something Else': An Approach to Encrypted Image Folding

A property of sparse representations in relation to their capacity for i...

Please sign up or login with your details

Forgot password? Click here to reset