D 2023

Data Loss Prevention Solution for Linux Endpoint Devices

DAUBNER, Lukáš and Adam POVAŽANEC

Basic information

Original name

Data Loss Prevention Solution for Linux Endpoint Devices

Authors

DAUBNER, Lukáš (203 Czech Republic, guarantor, belonging to the institution) and Adam POVAŽANEC (703 Slovakia, belonging to the institution)

Edition

United States, ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and Security, p. 1-10, 10 pp. 2023

Publisher

Association for Computing Machinery

Other information

Language

English

Type of outcome

Stať ve sborníku

Field of Study

10200 1.2 Computer and information sciences

Country of publisher

United States of America

Confidentiality degree

není předmětem státního či obchodního tajemství

Publication form

electronic version available online

References:

RIV identification code

RIV/00216224:14330/23:00131647

Organization unit

Faculty of Informatics

ISBN

979-8-4007-0772-8

UT WoS

001122662500126

Keywords in English

Data Loss Prevention; Auditing; Kernel Hooking; DLP; Data Leakage

Tags

International impact, Reviewed
Změněno: 7/4/2024 23:23, RNDr. Pavel Šmerk, Ph.D.

Abstract

V originále

Endpoint data loss prevention (DLP) software monitors and protects data on the endpoint against accidental and malicious leakage. While the risk of such leakage is widely present in current systems, it is more so within the intelligent infrastructures due to potential impact, heterogeneity, and complexity. However, there is a significant gap in open solutions for wide Linux-based endpoints. Therefore, this paper discusses possible approaches towards Linux endpoint DLP solution, which would be widely available on Linux distributions, not relying on fragile assumptions and not undermining security controls. Namely, the focus is on audit and control of file system operations and external USB devices. The viable approaches are discussed, and a prototype solution is implemented using the ftrace framework for file system operations and combining the udev subsystem and the sysfs virtual file system for external USB devices. While the solution is demonstrated in scenarios involving various DLP channels, it also established a platform for further research based on the data from intercepted events.

Links

MUNI/A/1389/2022, interní kód MU
Name: Aplikovaný výzkum na FI: Bezpečnost počítačových systémů, softwarových architektur kritických infrastruktur s forenzními aspekty, zpracování dat pokročilých sensorů a algoritmy plánování v dopravě a logistice
Investor: Masaryk University
MUNI/G/1142/2022, interní kód MU
Name: Forensic Support for Building Trust in Smart Software Ecosystems
Investor: Masaryk University, Forensic Support for Building Trust in Smart Software Ecosystems, INTERDISCIPLINARY - Interdisciplinary research projects