CloudFilter: practical control of sensitive data propagation to the cloud

CloudFilter: practical control of sensitive data propagation to the cloud
复制标题

DOI:
10.1145/2381913.2381931
复制
发表时间:
2012-10
期刊:
--
影响因子:
--
通讯作者:
I. Papagiannis;P. Pietzuch
I. Papagiannis;P. Pietzuch
中科院分区:
其他
文献类型:
--
作者:
I. Papagiannis;P. Pietzuch

文献摘要

相似文献

企业采用云服务的一个主要障碍是可能失去对敏感数据的控制。公司经常不得不保护他们的数据子集,因为它对他们的业务至关重要,或者他们被法律要求这样做。相比之下,云服务提供商在不提供担保的情况下处理企业数据,可能会危及机密性。为了保持对敏感数据的控制,公司通常会在网络级别阻止对各种云服务的所有访问。这些限制大大降低了员工的工作效率,同时在恶意员工面前提供的实际保护有限。在本文中,我们建议了一种实用的机制,以确保企业在允许员工使用云服务的同时保持对其敏感数据的控制。我们观察到大多数云服务使用HTTP作为传输协议。由于HTTP提供了定义良好的文件传输方法,因此检查HTTP消息允许独立于特定云服务的实现来监控企业和云服务之间的数据传播。我们的系统CloudFilter拦截到云服务的文件传输,执行日志记录并执行数据传播策略。CloudFilter控制文件上传到云后的传播位置,并确保只有经过授权的用户才能访问。我们展示了CloudFilter可以用于控制到Dropbox和GSS的数据传播,描述了它可以实施的现实数据传播策略。
A major obstacle for the adoption of cloud services in enterprises is the potential loss of control over sensitive data. Companies often have to safeguard a subset of their data because it is crucial to their business or they are required to do so by law. In contrast, cloud service providers handle enterprise data without providing guarantees and may put confidentiality at risk. In order to maintain control over their sensitive data, companies typically block all access to a wide range of cloud services at the network level. Such restrictions significantly reduce employee productivity while offering limited practical protection in the presence of malicious employees. In this paper, we suggest a practical mechanism to ensure that an enterprise maintains control of its sensitive data while employees are allowed to use cloud services. We observe that most cloud services use HTTP as a transport protocol. Since HTTP offers well-defined methods to transfer files, inspecting HTTP messages allows the propagation of data between the enterprise and cloud services to be monitored independently of the implementation of specific cloud services. Our system, CloudFilter, intercepts file transfers to cloud services, performs logging and enforces data propagation policies. CloudFilter controls where files propagate after they have been uploaded to the cloud and ensures that only authorised users may gain access. We show that CloudFilter can be applied to control data propagation to Dropbox and GSS, describing the realistic data propagation policies that it can enforce.