Back to results

University of Pennsylvania

Secure Time-Aware Provenance for Distributed Systems

Abstract

dc:description.abstract

Operators of distributed systems often find themselves needing to answer forensic questions, to perform a variety of managerial tasks including fault detection, system debugging, accountability enforcement, and attack analysis. In this dissertation, we present Secure Time-Aware Provenance (STAP), a novel approach that provides the fundamental functionality required to answer such forensic questions -- the capability to "explain" the existence (or change) of a certain distributed system state at a given time in a potentially adversarial environment. This dissertation makes the following contributions. First, we propose the STAP model, to explicitly represent time and state changes. The STAP model allows consistent and complete explanations of system state (and changes) in dynamic environments. Second, we show that it is both possible and practical to efficiently and scalably maintain and query provenance in a distributed fashion, where provenance maintenance and querying are modeled as recursive continuous queries over distributed relations. Third, we present security extensions that allow operators to reliably query provenance information in adversarial environments. Our extensions incorporate tamper-evident properties that guarantee eventual detection of compromised nodes that lie or falsely implicate correct nodes. Finally, the proposed research results in a proof-of-concept prototype, which includes a declarative query language for specifying a range of useful provenance queries, an interactive exploration tool, and a distributed provenance engine for operators to conduct analysis of their distributed systems. We discuss the applicability of this tool in several use cases, including Internet routing, overlay routing, and cloud data processing.

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Zhou, Wenchao
Advisor dc:contributor.advisor
  • Boon Thau Loo

Rights

dc:rights
Statement dc:rights
  • Wenchao Zhou
Language dc:language
en

Identifiers

dc:identifier.*
Repository record dc:identifier.uri
https://repository.upenn.edu/handle/20.500.14332/32363
OAI identifier oai:identifier
oai:repository.upenn.edu:20.500.14332/32363

Chain of custody

source
Harvested from
University of Pennsylvania
Base URL
repository.upenn.edu/server/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
related terms
citation

Zhou, Wenchao. Secure Time-Aware Provenance for Distributed Systems. 2012. https://repository.upenn.edu/handle/20.500.14332/32363