【24h】

Hypervisor-Based Sensitive Data Leakage Detector

机译:基于管理程序的敏感数据泄漏探测器

获取原文

摘要

Sensitive Data Leakage (SDL) is a major issue faced by organizations due to increasing reliance on data-driven decision-making. Existing Data Leakage Prevention (DLP) solutions are being challenged by the adoption of network transport encryption and the presence of privileged-mode malware designed to tamper with the DLP agent programs. We propose a novel DLP system called "HyperSweep" that uses Virtual Machine Memory Introspection (VMI) technology to inspect the memory content of a guest system for sensitive information. The approach is robust against both network transport encryption and malware that attack DLP agent programs. The HyperSweep prototype is implemented on top of the KVM hypervisor. Our experiments have confirmed its applicability to real-world applications, including web browsers, office applications, and social networking applications. The experiments also indicate moderate performance overhead from applying HyperSweep.
机译:敏感数据泄露(SDL)是组织面临的主要问题,因为越来越依赖于数据驱动的决策。通过网络传输加密以及设计用于篡改DLP代理程序的特权模式恶意软件的存在,正在挑战现有数据泄漏预防(DLP)解决方案。我们提出了一种名为“Hyperswew”的新型DLP系统,该系统使用虚拟机内存内省(VMI)技术来检查客户系统的内存内容以获取敏感信息。该方法对于攻击DLP代理程序的网络传输加密和恶意软件是强大的。高度潜水原型在KVM虚拟机管理程序的顶部实现。我们的实验已经证实了其对现实世界应用的适用性,包括Web浏览器,办公应用程序和社交网络应用程序。实验还表明施加超温度的适度性能开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号