Research Area

Cyber Recovery

Provenance-aware recovery that restores by knowledge significance and verifies integrity before trust is re-extended.

Recovery Is a Knowledge Problem

Conventional recovery answers a storage question: how quickly can systems and volumes be restored. The harder question after a serious incident is a knowledge question: which assets matter most, which can be trusted, and in what order should confidence be rebuilt.

Restoring data whose integrity cannot be demonstrated re-establishes availability while leaving the underlying uncertainty in place, and in a contaminated environment, that can restore the adversary's position along with the organization's.

Significance-Ordered Restoration

Our research develops recovery sequencing derived from provenance rather than from volume or schedule: assets whose loss propagates furthest through the dependency graph, and whose lineage supports the most downstream work, are prioritized.

This produces a restoration order that reflects institutional consequence instead of storage topology.

Verify Before Trust

Recovery should be gated on demonstrable integrity. Where a tamper-evident record exists, restoration can be accompanied by verification that the record has not been altered, and by localization of exactly where alteration occurred if it has.

That converts recovery from an act of hope into an act of evidence.

Key Elements

What It Comprises

Dependency Propagation

Bounded traversal to determine what a compromise actually exposes.

Significance Scoring

Restoration priority derived from lineage and impact.

Integrity Verification

Tamper-evidence checked before trust is re-extended.

Isolated Preservation

Assets held in states that survive the incident that prompted recovery.

Related

Continue Reading

Discuss This Work

We welcome technical and research conversations.