Provenance-aware recovery that restores by knowledge significance and verifies integrity before trust is re-extended.
Conventional recovery answers a storage question: how quickly can systems and volumes be restored. The harder question after a serious incident is a knowledge question: which assets matter most, which can be trusted, and in what order should confidence be rebuilt.
Restoring data whose integrity cannot be demonstrated re-establishes availability while leaving the underlying uncertainty in place, and in a contaminated environment, that can restore the adversary's position along with the organization's.
Our research develops recovery sequencing derived from provenance rather than from volume or schedule: assets whose loss propagates furthest through the dependency graph, and whose lineage supports the most downstream work, are prioritized.
This produces a restoration order that reflects institutional consequence instead of storage topology.
Recovery should be gated on demonstrable integrity. Where a tamper-evident record exists, restoration can be accompanied by verification that the record has not been altered, and by localization of exactly where alteration occurred if it has.
That converts recovery from an act of hope into an act of evidence.
Bounded traversal to determine what a compromise actually exposes.
Restoration priority derived from lineage and impact.
Tamper-evidence checked before trust is re-extended.
Assets held in states that survive the incident that prompted recovery.