CLAMP: Practical Prevention of Large-Scale Data Leaks

CLAMP: Practical Prevention of Large-Scale Data Leaks
复制标题

CLAMP:大规模数据泄露的实际预防

DOI:
10.1109/sp.2009.21
复制
发表时间:
2009
期刊:
2009 30th IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
A. Perrig
A. Perrig
中科院分区:
--
文献类型:
--
作者:
Bryan Parno;Jonathan M. McCune;Dan Wendlandt;David G. Andersen;A. Perrig

文献摘要

被引文献

相似文献

提供对敏感数据的在线访问使Web服务器成为攻击者的有利可图的目标。Web服务器的任何脚本、应用程序或操作系统的任何漏洞都可能泄露数百万客户的敏感数据。不幸的是,许多用于阻止数据泄漏的系统需要应用程序开发人员付出相当大的努力,这阻碍了它们的采用。在这项工作中,我们调查了如何以最少的开发人员努力来防止此类泄漏。我们提出了CLAMP,这是一种即使在存在Web服务器泄露或SQL注入攻击的情况下也能防止数据泄漏的体系结构。CLAMP通过对用户数据实施强大的访问控制并隔离代表不同用户运行的代码来保护敏感数据。通过专注于最大限度地减少开发人员的工作,我们得到了一种体系结构,允许开发人员使用熟悉的操作系统、服务器和脚本语言,同时对应用程序代码进行相对较少的更改--我们的应用程序中不到50行。
Providing online access to sensitive data makes web servers lucrative targets for attackers. A compromise of any of the web server's scripts, applications, or operating system can leak the sensitive data of millions of customers. Unfortunately, many systems for stopping data leaks require considerable effort from application developers, hindering their adoption.In this work, we investigate how such leaks can be prevented with minimal developer effort. We propose CLAMP, an architecture for preventing data leaks even in the presence of web server compromises or SQL injection attacks. CLAMP protects sensitive data by enforcing strong access control on user data and by isolating code running on behalf of different users. By focusing on minimizing developer effort, we arrive at an architecture that allows developers to use familiar operating systems, servers, and scripting languages, while making relatively few changes to application code -- less than 50 lines in our applications.