uit-inf-3203 / Course

Course material and information for the INF-3203 course at UiT
5 stars 0 forks source link

Questions for "Asynchronous intrusion recovery..." #11

Closed fjukstad closed 9 years ago

fjukstad commented 9 years ago

Hi @uit-inf-3203/students !

Here's the list of questions for Eiriks presentation about "Asynchronous intrusion recovery for interconnected web services" on Thursday.

  1. When there are several services involved with aire, how does one with absolute certainty know that for example a “delete”/”Create” operation is not from an attacker on another service? Magnus Wikstad
  2. How can a service be rolled back if a transaction from a bank account is already withdrawn? Even if the money is not withdrawn, banks usually reserves the transaction. Saeed Shariati
  3. What if the repair API is attacked? It now has the ability to go change history, replace request and responses, add and remove log entries. Is there a repair repair API API? Mats Christian Sørensen
  4. In the example they use 3 services. Let’s say you add 7 more so we have a total of 10 services. Will it work with so many services? Vi Tran
  5. Are there other services that can be combined that would benefit from aire? Johannes Arctander Larsen

Bjørn