DocumentCode :
2103875
Title :
Privacy-aware: Tracking and protecting sensitive information using automatic type inference
Author :
Ouyang, Weiwei
Author_Institution :
Enterprise Data Manage., State Street Technol. (Zhejiang) Co., Ltd., Hangzhou, China
fYear :
2010
fDate :
17-19 Dec. 2010
Firstpage :
665
Lastpage :
668
Abstract :
It is very hard to ensure that software is free of sensitive information leaks because current common software takes very little measures to control sensitive data propagation or limit data lifetime. We present Privacy-Aware, a sensitive data tracker and eraser based on type qualifier inference. We have adapted a simplified type qualifier inference to the LLVM framework, a low-level virtual machine infrastructure for a batch of languages. With type qualifier inference, Privacy-Aware can automatically reason about where the sensitive data has been propagated to and erase them before deallocation. We optimize Privacy-Aware with alias analysis and points-to analysis so that Privacy-Aware can be used as an effective annotation system for programmer to reduce the data lifetime in software development with minimal annotation effort. We have implemented Privacy-Aware by LLVM-based instrumentation. The preliminary evaluation suggests that Privacy-Aware can effectively clear sensitive data while only incurring a small amount of overhead, on average below 10%, in our benchmark. Our research provides evidence that requiring minimal programmer intervention, Privacy-Aware is an effective, efficient and autonomous strategy in privacy protection.
Keywords :
data privacy; security of data; software engineering; virtual machines; LLVM framework; alias analysis; automatic type inference; effective annotation system; low-level virtual machine infrastructure; minimal programmer intervention; points-to analysis; privacy-aware; sensitive data eraser; sensitive data tracker; sensitive information protection; sensitive information tracking; software development; type qualifier inference; Instruments; Kernel; Optimization; Privacy; Resource management; Security; privacy protection; secure deallocation; taint analysis; type qualifier;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Theory and Information Security (ICITIS), 2010 IEEE International Conference on
Conference_Location :
Beijing
Print_ISBN :
978-1-4244-6942-0
Type :
conf
DOI :
10.1109/ICITIS.2010.5689484
Filename :
5689484
Link To Document :
بازگشت