Efficient DLP-visor: An efficient hypervisor-based DLP

Michael Kiperberg, Guy Amit, Amir Yeshooroon, Nezer J. Zaidenberg

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

7 Scopus citations

Abstract

Many organization consider insider threat for data theft to be one of the most severe threats. An insider may also leak sensitive information without malicious intent (as a result of social engineering) Data leakage prevention (DLP) systems attempt to prevent intentional or accidental disclosure of sensitive information by monitoring the content or the context in which the information is transferred, for example, in a file system, an email server, instant messengers. We present a context-sensitive DLP system, called Efficient DLP-Visor. We implemented DLP-visor as a thin hypervisor capable of intercepting system calls in Windows operating systems equipped with Kernel Patch Protection. By intercepting system calls that govern the file system, inter-process communications, networking, system register and system clipboard, DLP-Visor guarantees that sensitive information can never leave a predefined set of directories. The performance overhead of Efficient DLP-Visor (7.2%) allows its deployment in real-world applications. Efficient DLP-visor logs were improved for better detection and logging of a DLP event. On idle time Efficient DLP-visor deletes most of the data log while maintaining the important data of leaks and attack.

Original languageEnglish
Title of host publicationProceedings - 21st IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing, CCGrid 2021
EditorsLaurent Lefevre, Stacy Patterson, Young Choon Lee, Haiying Shen, Shashikant Ilager, Mohammad Goudarzi, Adel N. Toosi, Rajkumar Buyya
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages344-355
Number of pages12
ISBN (Electronic)9781728195865
DOIs
StatePublished - May 2021
Externally publishedYes
Event21st IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing, CCGrid 2021 - Virtual, Melbourne, Australia
Duration: 10 May 202113 May 2021

Publication series

NameProceedings - 21st IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing, CCGrid 2021

Conference

Conference21st IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing, CCGrid 2021
Country/TerritoryAustralia
CityVirtual, Melbourne
Period10/05/2113/05/21

Fingerprint

Dive into the research topics of 'Efficient DLP-visor: An efficient hypervisor-based DLP'. Together they form a unique fingerprint.

Cite this