首页> 外文会议>Network and Distributed System Security Symposium >PRECIP: Towards Practical and Retrofittable Confidential Information Protection
【24h】

PRECIP: Towards Practical and Retrofittable Confidential Information Protection

机译:避孕:走向实用和退换的机密信息保护

获取原文

摘要

A grand challenge in information protection is how to preserve the confidentiality of sensitive information under spyware surveillance. This problem has not been well addressed by the existing access-control mechanisms which cannot prevent the spyware already in a system from monitoring an authorized party's interactions with sensitive data. Our answer to this challenge is PRECIP, a new security policy model which takes a first step towards practical and retrofittable confidential information protection. This model is designed to offer efficient online protection for commercial applications and operating systems. It intends to be retrofitted to these applications and systems without modifying their code. To this end, PRECIP addresses several practical issues critical to containing spyware surveillance, which however are not well handled by the previous work in access control and information-flow security. Examples include the models for human input devices such as keyboard whose sensitivity level must be dynamically determined, other shared resources such as clipboard and screen which must be accessed by different processes, and the multitasked processes which work on public and sensitive data concurrently. We applied PRECIP to Windows XP to protect the applications for editing or viewing sensitive documents and browsing sensitive websites. We demonstrate that our implementation works effectively against a wide spectrum of spyware, including keyloggers, screen grabbers and file stealers. We also evaluated the overheads of our technique, which are shown to be very small.
机译:在信息保护隆重的挑战是如何保持在间谍软件监视的敏感信息的保密性。这个问题一直没有得到很好的利用,不能阻止间谍软件已经在系统从监控敏感数据的授权方的互动现有的访问控制机制解决。我们应对这一挑战是PRECIP,新的安全策略模型,需要对实用性和可改装的机密信息保护的第一步。这种模式是专门提供商业应用程序和操作系统高效的在线保护。它打算加装到这些应用程序和系统,而无需修改其代码。为此,PRECIP地址包含间谍软件监视,然而这不是由访问控制和信息流安全的前期工作以及处理关键的几个实际问题。实例包括人类输入设备,如键盘,其灵敏度电平必须被动态地确定,其他共享资源如剪贴板和必须由不同的过程来访问屏幕,并且多任务处理,其对公众和敏感数据工作并发模型。我们应用PRECIP到Windows XP保护的应用程序进行编辑或查看敏感文件和浏览敏感网站。我们证明了我们的实施有效地工作对间谍软件的广泛,包括键盘记录,屏幕抓取器和文件窃取。我们还评估了我们技术的费用,这是证明是非常小的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号