DocumentCode :
588626
Title :
Data Loss Prevention Based on Data-Driven Usage Control
Author :
Wuchner, Tobias ; Pretschner, Alexander
Author_Institution :
Tech. Univ. Munchen, Garching, Germany
fYear :
2012
fDate :
27-30 Nov. 2012
Firstpage :
151
Lastpage :
160
Abstract :
Inadvertent data disclosure by insiders is considered as one of the biggest threats for corporate information security. Data loss prevention systems typically try to cope with this problem by monitoring access to confidential data and preventing their leakage or improper handling. Current solutions in this area, however, often provide limited means to enforce more complex security policies that for instance specify temporal or cardinal constraints on the execution of events. This paper presents UC4Win, a data loss prevention solution for Microsoft Windows operating systems that is based on the concept of data-driven usage control to allow such a fine-grained policy-based protection. UC4Win is capable of detecting and controlling data-loss related events at the level of individual function calls. This is done with function call interposition techniques to intercept application calls to the Windows API in combination with methods to track the flows of confidential data through the system.
Keywords :
application program interfaces; business data processing; operating systems (computers); security of data; user interfaces; Microsoft Windows operating systems; UC4Win; Windows API; cardinal constraints; complex security policies; confidential data monitoring access; corporate information security; data loss prevention systems; data-driven usage control; data-loss related event control; data-loss related event detection; event execution; fine-grained policy-based protection; function call interposition techniques; improper handling; inadvertent data disclosure; individual function calls; temporal constraints; Business; Containers; Context; Data models; Kernel; Monitoring; Security; data loss prevention; dynamic data flow tracking; microsoft windows security; usage control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Reliability Engineering (ISSRE), 2012 IEEE 23rd International Symposium on
Conference_Location :
Dallas, TX
ISSN :
1071-9458
Print_ISBN :
978-1-4673-4638-2
Type :
conf
DOI :
10.1109/ISSRE.2012.10
Filename :
6405363
Link To Document :
بازگشت