• DocumentCode
    267177
  • Title

    A Mantrap-Inspired, User-Centric Data Leakage Prevention (DLP) Approach

  • Author

    Ko, Ryan K. L. ; Tan, Alan Y. S. ; Ting Gao

  • Author_Institution
    Dept. of Comput. Sci. Fac. of Comput. & Math. Sci., Univ. of Waikato Hamilton, Hamilton, New Zealand
  • fYear
    2014
  • fDate
    15-18 Dec. 2014
  • Firstpage
    1033
  • Lastpage
    1039
  • Abstract
    The ease of sharing information through the Internet and Cloud Computing inadvertently introduces a growing problem of data leakages. At the same time, many end-users are unaware that their data was leaked or stolen since most data is leaked by operations running in the background. This paper introduces a novel user-centric, mantrap-inspired data leakage prevention (DLP) approach that can discover, present any sending of data -- both authorized and unauthorized -- to end-users and subsequently provide them the ability to stop the sending process. We implemented our own kernel module to work together with our user-space program in getting user´s approval for every sending process -- giving the user full control over all outbound data sending process in their devices. With this, the end-user can always decide which data sending process should be allowed or blocked. This overcomes the limitations of current, often inflexible and inaccurate DLP solutions depending on pre-set rules and content detection. We showcase a proof-of-concept for our new way of detecting data leakages in an end user´s device. This paves the way for further research covering more complex data stealing techniques, such as the use of covert channels.
  • Keywords
    cloud computing; security of data; DLP approach; Internet; cloud computing; content detection; data stealing techniques; information sharing; kernel module; mantrap-inspired approach; outbound data sending process; preset rules; user-centric data leakage prevention approach; user-space program; Hardware; Kernel; Linux; Malware; Message systems; Organizations; Data leakage prevention; cloud computing; kernel module; user-centric security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing Technology and Science (CloudCom), 2014 IEEE 6th International Conference on
  • Conference_Location
    Singapore
  • Type

    conf

  • DOI
    10.1109/CloudCom.2014.23
  • Filename
    7037802