Data Loss Prevention Solution for Linux Endpoint Devices
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216224%3A14330%2F23%3A00131647" target="_blank" >RIV/00216224:14330/23:00131647 - isvavai.cz</a>
Result on the web
<a href="http://dx.doi.org/10.1145/3600160.3605036" target="_blank" >http://dx.doi.org/10.1145/3600160.3605036</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1145/3600160.3605036" target="_blank" >10.1145/3600160.3605036</a>
Alternative languages
Result language
angličtina
Original language name
Data Loss Prevention Solution for Linux Endpoint Devices
Original language description
Endpoint data loss prevention (DLP) software monitors and protects data on the endpoint against accidental and malicious leakage. While the risk of such leakage is widely present in current systems, it is more so within the intelligent infrastructures due to potential impact, heterogeneity, and complexity. However, there is a significant gap in open solutions for wide Linux-based endpoints. Therefore, this paper discusses possible approaches towards Linux endpoint DLP solution, which would be widely available on Linux distributions, not relying on fragile assumptions and not undermining security controls. Namely, the focus is on audit and control of file system operations and external USB devices. The viable approaches are discussed, and a prototype solution is implemented using the ftrace framework for file system operations and combining the udev subsystem and the sysfs virtual file system for external USB devices. While the solution is demonstrated in scenarios involving various DLP channels, it also established a platform for further research based on the data from intercepted events.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
10200 - Computer and information sciences
Result continuities
Project
—
Continuities
S - Specificky vyzkum na vysokych skolach
Others
Publication year
2023
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and Security
ISBN
9798400707728
ISSN
—
e-ISSN
—
Number of pages
10
Pages from-to
1-10
Publisher name
Association for Computing Machinery
Place of publication
United States
Event location
Benevento, Italy
Event date
Aug 29, 2023
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
001122662500126