首页> 中文期刊> 《电子学报:英文版》 >CPSec DLP: Kernel-Level Content Protection Security System of Data Leakage Prevention

CPSec DLP: Kernel-Level Content Protection Security System of Data Leakage Prevention

         

摘要

Data leakage prevention(DLP) is very important for sensitive or unauthorized data protection, however, most current DLP technologies are based on content monitor, detection and filtering, which can be easily bypassed or cheated. We propose a thorough and highlevel Content protection secure scheme of DLP(CPSec DLP) based on kernel-level mandatory encryption, in which we proposed mutual authentication and key agreement method between client and server, and we adopted SM2 algorithm for session key management; and we propose kernel-level mandatory secure middleware for unstructured data protection, in which the secure middleware works in File system driver(FSD) layer supporting for'write-encryption, open-decryption' operation, once the data is written to storage space either in hard-disk or USB disk the data is mandatorily encrypted, while when the data is open the mandatory secure middleware decrypts the data to plain in system memory. Moreover we propose data share and delivery among domain internal users and external customers. In the CPSec DLP scheme, the encryption algorithms, security policy and rules can be dynamically parameterized when necessary, while in the lifecycle the data management can only be used according to its usage control rules, such as read-only, write, save, print,export, backup rights. Upon the proposed CPSec DLP, we implemented the CPSec DLP system in kernel-level driver layer based on FSD, which supports parameterized process and document format for unstructured data leakage protection. Large amount of experiments manifest the proposed scheme is secure, reliable, extendible and efficient for kinds of format unstructured data leakage protection.

著录项

  • 来源
    《电子学报:英文版》 |2017年第4期|P.827-836|共10页
  • 作者

    MA Zhaofeng;

  • 作者单位

    School of Cyberspace Security Beijing University of Posts and Telecommunications;

  • 原文格式 PDF
  • 正文语种 chi
  • 中图分类
  • 关键词

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号