Privacy analysis and enhancements for data sharing in *nix systems

  • Authors:
  • Aameek Singh;Ling Liu;Mustaque Ahamad

  • Affiliations:
  • Storage Systems, IBM Almaden Research Center, 650 Harry Road, San Jose, CA – 95120, USA.;College of Computing, Georgia Insitute of Technology, 801 Atlantic Drive, Atlanta, GA – 30332, USA.;College of Computing, Georgia Insitute of Technology, 801 Atlantic Drive, Atlanta, GA – 30332, USA.

  • Venue:
  • International Journal of Information and Computer Security
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we analyse the data sharing mechanisms of *nixsystems and identify an immediate need for better privacy support.For example, using a simple insider attack we were able to accessover 84 GB of private data at one organisation of 825 users,including 300 000 e-mails and 579 passwords to financial and otherprivate services websites, without exploiting any technicalvulnerability. We present two solutions to address this problem: 1.an administrative auditing tool which can alert administrators andusers when their private data is at risk; 2. a new View BasedAccess Control (VBAC) mechanism which provides stronger and yetconvenient privacy support. We also describe a proof-of-conceptfilesystem-based implementation and performance analysis of VBAC.Our evaluations with three well-known filesystem benchmarks showlittle overhead of using VBAC.