首页> 外文会议>IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing >Efficient DLP-visor: An efficient hypervisor-based DLP
【24h】

Efficient DLP-visor: An efficient hypervisor-based DLP

机译:高效DLP-Visor:基于高效的管理程序的DLP

获取原文

摘要

Many organization consider insider threat for data theft to be one of the most severe threats. An insider may also leak sensitive information without malicious intent (as a result of social engineering) Data leakage prevention (DLP) systems attempt to prevent intentional or accidental disclosure of sensitive information by monitoring the content or the context in which the information is transferred, for example, in a file system, an email server, instant messengers. We present a context-sensitive DLP system, called Efficient DLP-Visor. We implemented DLP-visor as a thin hypervisor capable of intercepting system calls in Windows operating systems equipped with Kernel Patch Protection. By intercepting system calls that govern the file system, inter-process communications, networking, system register and system clipboard, DLP-Visor guarantees that sensitive information can never leave a predefined set of directories. The performance overhead of Efficient DLP-Visor (7.2%) allows its deployment in real-world applications. Efficient DLP-visor logs were improved for better detection and logging of a DLP event. On idle time Efficient DLP-visor deletes most of the data log while maintaining the important data of leaks and attack.
机译:许多组织考虑内部威胁数据盗窃是最严重的威胁之一。内幕人员还可以泄漏敏感信息而没有恶意意图(由于社会工程)数据泄漏预防(DLP)系统试图通过监视传输信息的内容或上下文来防止有意或意外披露敏感信息的敏感信息。示例,在文件系统中,电子邮件服务器,即时消息。我们介绍了一个中文敏感的DLP系统,称为高效的DLP-Visor。我们将DLP-Visor作为一个能够在配备内核补丁保护的Windows操作系统中拦截系统呼叫的薄虚拟机管理程序。通过拦截管理文件系统的系统调用,进程间通信,网络,系统寄存器和系统剪贴板,DLP-Visor保证敏感信息永远不会留下预定的一组目录。高效DLP-Visor的性能开销(7.2%)允许其部署在现实世界中。提高了高效的DLP遮阳板日志,以便更好地检测和记录DLP事件。在空闲时间高效DLP-Visor删除大多数数据日志,同时保持泄漏和攻击的重要数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号