File System Minifilter Based Data Leakage Prevention System

Adrian Buda, Adrian Colesa
{"title":"File System Minifilter Based Data Leakage Prevention System","authors":"Adrian Buda, Adrian Colesa","doi":"10.1109/ROEDUNET.2018.8514147","DOIUrl":null,"url":null,"abstract":"In recent years, more and more companies and institutions tend to keep most of their data in digital format. There is a large specter of information stored by such entities, like medical records, contracts, internal procedures, etc. that can be considered as being confidential, thus protecting them is a great concern. Since employees have access to such information, either by negligence or bad intention, they could leak the aforementioned information. As a solution to the given problem, our implementation is based on a file system mini filter driver that will block potentially unwanted file system operations, such as copying a confidential file to a removable storage device. The aforementioned architecture allows us to intercept and block I/O requests that originate from CopyFile or ReadFileAPIs. Another feature consists in blocking external devices such as SD cards, USB drives or external hard drives (the drives are detected, assigned a drive letter, but no further operations are allowed).","PeriodicalId":407088,"journal":{"name":"2018 17th RoEduNet Conference: Networking in Education and Research (RoEduNet)","volume":"63 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 17th RoEduNet Conference: Networking in Education and Research (RoEduNet)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ROEDUNET.2018.8514147","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

In recent years, more and more companies and institutions tend to keep most of their data in digital format. There is a large specter of information stored by such entities, like medical records, contracts, internal procedures, etc. that can be considered as being confidential, thus protecting them is a great concern. Since employees have access to such information, either by negligence or bad intention, they could leak the aforementioned information. As a solution to the given problem, our implementation is based on a file system mini filter driver that will block potentially unwanted file system operations, such as copying a confidential file to a removable storage device. The aforementioned architecture allows us to intercept and block I/O requests that originate from CopyFile or ReadFileAPIs. Another feature consists in blocking external devices such as SD cards, USB drives or external hard drives (the drives are detected, assigned a drive letter, but no further operations are allowed).
基于文件系统Minifilter的数据泄漏防护系统
近年来,越来越多的公司和机构倾向于以数字格式保存大部分数据。这些实体存储的大量信息,如医疗记录、合同、内部程序等,可被视为机密,因此保护它们是一个非常值得关注的问题。由于员工可以接触到这些信息,无论是疏忽还是恶意,他们都可能泄露上述信息。作为给定问题的解决方案,我们的实现基于文件系统迷你过滤器驱动程序,该驱动程序将阻止可能不需要的文件系统操作,例如将机密文件复制到可移动存储设备。上述架构允许我们拦截和阻止来自CopyFile或readfileapi的I/O请求。另一个功能包括阻止外部设备,如SD卡、USB驱动器或外部硬盘驱动器(驱动器被检测到,分配一个驱动器号,但不允许进一步操作)。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信