arrow
返回

Hindering data theft with encrypted data trees

delete2015-03-01
delete11
delete
OA
AI
J
Jorge Blasco *
J
Juan Tapiador
P
Pedro Peris‐Lopez
G
Guillermo Suárez‐Tangil
DOI:10.1016/j.jss.2014.11.050delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Data theft is a major threat for modern organizations with potentially large economic consequences. Although these attacks may well originate outside an organization's information systems, the attacker or else an insider must eventually-make contact with the system where the information resides and extract it. In this work, we propose a scheme that hinders unauthorized data extraction by modifying the basic file system primitives used to access files. Intuitively, our proposal emulates the chains used to protect valuable items in certain clothing shopping centers, where shoplifting is prevented by forcing the thief to steal the whole rack of items. We achieve this by encrypting sensitive files using nonces (i.e., pseudorandom numbers used only once) as keys. Such nonces are available, also in encrypted form, in other objects of the file system. The system globally resembles a distributed Merkle hash tree, in such a way that getting access to a file requires previous access to a number of other files. This forces any potential attacker to extract not only the targeted sensitive information, but also all the files chained to it that are necessary to compute the associated key. Furthermore, our scheme incorporates a probabilistic rekeying mechanism to limit the damage that might be caused by patient extractors. We report experimental results measuring the time overhead introduced by our proposal and compare it with the effort an attacker would need to successfully extract information from the system. Our results show that the scheme increases substantially the effort required by an insider, while the introduced overhead is feasible for standard computing platforms. (C) 2014 Elsevier Inc. All rights reserved.
Keyword:
Data leakage prevention
Insiders
Information theft
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Journal of Systems and Software 封面图
Journal of Systems and Software
IF:
4.1
论文数:
5.4K
被引数:
8.4K

机构

U
Universidad Carlos III de Madrid
学者数:
5.5K
论文数: 5.7K
被引数: 4.5K
引用论文

引用论文

Nutritional Value of Chenopodium quinoa Seeds Obtained from an Open Field Culture Under Saline Conditions
err2016-01-01
err0
PREAI
errMeryem Brakez; Salma Daoud; Moulay Chérif Harrouni; Naima Tachbibi; Zahra Brakez
err分享
err收藏
Enzyme Chemistry
err1958-02-01
err0
errOAAI
errF. DICKENS
err分享
err收藏
err
IF0
err
err0
PREAI
err
err分享
err收藏
A novel DRM framework for peer-to-peer music content delivery
err2010-10-01
err11
PREAI
errLi, Jung-Shian; Hsieh, Che-Jen; Hung, Cheng-Fu
err分享
err收藏
Bypassing information leakage protection with trusted applications
err2012-06-01
err10
PREAI
errBlasco, Jorge; Hernandez-Castro, Julio Cesar; Tapiador, Juan E.; Ribagorda, Arturo
err分享
err收藏
err分享
err收藏
Insiders Behaving Badly: Addressing Bad Actors and Their Actions
err2010-03-01
err64
PREAI
errPfleeger, Shari Lawrence; Predd, Joel B.; Hunker, Jeffrey; Bulford, Carla
err分享
err收藏
没有更多内容