{"id":"https://openalex.org/W2613747361","doi":"https://doi.org/10.1145/3035918.3064037","title":"ACIDRain","display_name":"ACIDRain","publication_year":2017,"publication_date":"2017-05-09","ids":{"openalex":"https://openalex.org/W2613747361","doi":"https://doi.org/10.1145/3035918.3064037","mag":"2613747361"},"language":"en","primary_location":{"id":"doi:10.1145/3035918.3064037","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3035918.3064037","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2017 ACM International Conference on Management of Data","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5065146377","display_name":"Todd Warszawski","orcid":null},"institutions":[{"id":"https://openalex.org/I97018004","display_name":"Stanford University","ror":"https://ror.org/00f54p054","country_code":"US","type":"education","lineage":["https://openalex.org/I97018004"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Todd Warszawski","raw_affiliation_strings":["Stanford University, Stanford, CA, USA"],"affiliations":[{"raw_affiliation_string":"Stanford University, Stanford, CA, USA","institution_ids":["https://openalex.org/I97018004"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5002538469","display_name":"Peter Bailis","orcid":"https://orcid.org/0000-0003-1166-7823"},"institutions":[{"id":"https://openalex.org/I97018004","display_name":"Stanford University","ror":"https://ror.org/00f54p054","country_code":"US","type":"education","lineage":["https://openalex.org/I97018004"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Peter Bailis","raw_affiliation_strings":["Stanford University, Stanford, CA, USA"],"affiliations":[{"raw_affiliation_string":"Stanford University, Stanford, CA, USA","institution_ids":["https://openalex.org/I97018004"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5065146377"],"corresponding_institution_ids":["https://openalex.org/I97018004"],"apc_list":null,"apc_paid":null,"fwci":3.1119,"has_fulltext":false,"cited_by_count":48,"citation_normalized_percentile":{"value":0.93281087,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"5","last_page":"20"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10772","display_name":"Distributed systems and fault tolerance","score":0.9976000189781189,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9951000213623047,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8715426921844482},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.7617394924163818},{"id":"https://openalex.org/keywords/concurrency","display_name":"Concurrency","score":0.7130745053291321},{"id":"https://openalex.org/keywords/isolation","display_name":"Isolation (microbiology)","score":0.5980302095413208},{"id":"https://openalex.org/keywords/database-transaction","display_name":"Database transaction","score":0.5842975378036499},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5407363176345825},{"id":"https://openalex.org/keywords/concurrency-control","display_name":"Concurrency control","score":0.522010862827301},{"id":"https://openalex.org/keywords/transaction-processing","display_name":"Transaction processing","score":0.4783172905445099},{"id":"https://openalex.org/keywords/attack-surface","display_name":"Attack surface","score":0.4601393938064575},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.4500444829463959},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.343657910823822},{"id":"https://openalex.org/keywords/distributed-computing","display_name":"Distributed computing","score":0.27891018986701965}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8715426921844482},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.7617394924163818},{"id":"https://openalex.org/C193702766","wikidata":"https://www.wikidata.org/wiki/Q1414548","display_name":"Concurrency","level":2,"score":0.7130745053291321},{"id":"https://openalex.org/C2775941552","wikidata":"https://www.wikidata.org/wiki/Q25212305","display_name":"Isolation (microbiology)","level":2,"score":0.5980302095413208},{"id":"https://openalex.org/C75949130","wikidata":"https://www.wikidata.org/wiki/Q848010","display_name":"Database transaction","level":2,"score":0.5842975378036499},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5407363176345825},{"id":"https://openalex.org/C84511453","wikidata":"https://www.wikidata.org/wiki/Q2914952","display_name":"Concurrency control","level":3,"score":0.522010862827301},{"id":"https://openalex.org/C72108876","wikidata":"https://www.wikidata.org/wiki/Q844565","display_name":"Transaction processing","level":3,"score":0.4783172905445099},{"id":"https://openalex.org/C2776576444","wikidata":"https://www.wikidata.org/wiki/Q303569","display_name":"Attack surface","level":2,"score":0.4601393938064575},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.4500444829463959},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.343657910823822},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.27891018986701965},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C89423630","wikidata":"https://www.wikidata.org/wiki/Q7193","display_name":"Microbiology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3035918.3064037","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3035918.3064037","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2017 ACM International Conference on Management of Data","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.8199999928474426}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":48,"referenced_works":["https://openalex.org/W123548525","https://openalex.org/W1497959280","https://openalex.org/W1545155892","https://openalex.org/W1553894716","https://openalex.org/W1559255981","https://openalex.org/W1563849906","https://openalex.org/W1601925768","https://openalex.org/W1658853941","https://openalex.org/W1963979953","https://openalex.org/W1972544179","https://openalex.org/W1983119041","https://openalex.org/W1991199257","https://openalex.org/W1997354355","https://openalex.org/W2002179840","https://openalex.org/W2010042648","https://openalex.org/W2052987550","https://openalex.org/W2055908644","https://openalex.org/W2057583008","https://openalex.org/W2062194413","https://openalex.org/W2077693819","https://openalex.org/W2101027550","https://openalex.org/W2103087173","https://openalex.org/W2110908283","https://openalex.org/W2117780839","https://openalex.org/W2117917070","https://openalex.org/W2120476011","https://openalex.org/W2121053357","https://openalex.org/W2128453996","https://openalex.org/W2133662847","https://openalex.org/W2134747058","https://openalex.org/W2138536231","https://openalex.org/W2149984854","https://openalex.org/W2150086571","https://openalex.org/W2153649450","https://openalex.org/W2156428492","https://openalex.org/W2167744164","https://openalex.org/W2293215590","https://openalex.org/W2294903570","https://openalex.org/W2524165724","https://openalex.org/W2529843452","https://openalex.org/W2737641788","https://openalex.org/W2950295001","https://openalex.org/W3137220996","https://openalex.org/W4236306709","https://openalex.org/W4238388226","https://openalex.org/W6633288084","https://openalex.org/W6682812935","https://openalex.org/W6696803032"],"related_works":["https://openalex.org/W2150179797","https://openalex.org/W2170147831","https://openalex.org/W4242696047","https://openalex.org/W1985641955","https://openalex.org/W2588995807","https://openalex.org/W1491227338","https://openalex.org/W4312347827","https://openalex.org/W281655402","https://openalex.org/W1826152083","https://openalex.org/W2129824310"],"abstract_inverted_index":{"In":[0,12,60],"theory,":[1],"database":[2,14,166],"transactions":[3,15],"protect":[4],"application":[5],"data":[6],"from":[7],"corruption":[8],"and":[9,30,58,195,203,219],"integrity":[10],"violations.":[11],"practice,":[13],"frequently":[16],"execute":[17],"under":[18,47,138],"weak":[19,129],"isolation":[20,130,151],"that":[21,161,209],"exposes":[22],"programs":[23],"to":[24,34,131,168,185,212],"a":[25,65,100,112,145,180],"range":[26],"of":[27,68,102,128,165,174],"concurrency":[28],"anomalies,":[29],"programmers":[31],"may":[32],"fail":[33],"correctly":[35],"employ":[36],"transactions.":[37],"While":[38],"low":[39],"transaction":[40],"volumes":[41],"mask":[42],"many":[43],"potential":[44,120,134,150],"concurrency-related":[45,83],"errors":[46],"normal":[48],"operation,":[49],"determined":[50],"adversaries":[51],"can":[52],"exploit":[53],"them":[54],"programmatically":[55,86],"for":[56,121,135,148],"fun":[57],"profit.":[59],"this":[61],"paper,":[62],"we":[63,124],"formalize":[64],"new":[66],"kind":[67],"attack":[69,109],"on":[70,197],"database-backed":[71],"applications":[72,103,190],"called":[73,156],"an":[74,79],"ACIDRain":[75,94,122,207],"attack,":[76],"in":[77,99,104,153,192],"which":[78,110],"adversary":[80],"systematically":[81],"exploits":[82],"vulnerabilities":[84],"via":[85],"accessible":[87],"APIs.":[88],"These":[89],"attacks":[90,95,208],"are":[91],"not":[92],"theoretical:":[93],"have":[96],"already":[97],"occurred":[98],"handful":[101],"the":[105,119,126,172],"wild,":[106],"including":[107],"one":[108],"bankrupted":[111],"popular":[113,187],"Bitcoin":[114],"exchange.":[115],"To":[116],"proactively":[117],"detect":[118],"attacks,":[123],"extend":[125],"theory":[127],"analyze":[132],"latent":[133],"non-serializable":[136],"behavior":[137],"concurrent":[139,176],"web":[140,154],"API":[141],"calls.":[142],"We":[143,178,201],"introduce":[144],"language-agnostic":[146],"method":[147],"detecting":[149],"anomalies":[152],"applications,":[155],"Abstract":[157],"Anomaly":[158],"Detection":[159],"(2AD),":[160],"uses":[162],"dynamic":[163],"traces":[164],"accesses":[167],"efficiently":[169],"reason":[170],"about":[171],"space":[173],"possible":[175],"interleavings.":[177],"apply":[179],"prototype":[181],"2AD":[182],"analysis":[183],"tool":[184],"12":[186],"self-hosted":[188],"eCommerce":[189],"written":[191],"four":[193],"languages":[194],"deployed":[196],"over":[198],"2M":[199],"websites.":[200],"identify":[202],"verify":[204],"22":[205],"critical":[206],"allow":[210],"attackers":[211],"corrupt":[213],"store":[214],"inventory,":[215],"over-spend":[216],"gift":[217],"cards,":[218],"steal":[220],"inventory.":[221]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":11},{"year":2022,"cited_by_count":8},{"year":2021,"cited_by_count":4},{"year":2020,"cited_by_count":4},{"year":2019,"cited_by_count":5},{"year":2018,"cited_by_count":4},{"year":2017,"cited_by_count":2}],"updated_date":"2026-03-13T16:22:10.518609","created_date":"2017-05-19T00:00:00"}
