TightLip: Keeping Applications from Spilling the Beans (presented with demo)

نویسندگان

  • Aydan Yumerefendi
  • Benjamin Mickle
  • Landon P. Cox
چکیده

Managing the permissions of any shared space is challenging, even for highly skilled computer users. This task is particularly daunting for untrained PC users, for whom access control errors are routine and can lead to damaging privacy leaks. A 2003 usability study of the Kazaa peer-to-peer file-sharing network found that many users share their entire hard drive with the rest of the Internet, including email inboxes and credit card information. Over 12 hours, the study found 156 distinct users who were sharing their email inboxes. Not only were these files available for download, but other users could be observed downloading them. This and similar compromises such as users inadvertently copying sensitive data into their public web space present a different threat model than is normally assumed by the privacy and security literature. In these cases, data leaked due to access control misconfigurations rather than malice or buggy software. For example, companies in the UK were reported to have banned their employees from using Google Desktop because it allows users to search across machines and can store sensitive files on remote Google servers. Neither secure communication channels nor hostbased intrusion detection would have prevented these exposures. Furthermore, the impact of these leaks extends beyond the negligent users themselves since the leaked data can and often does include previous communication and transaction records involving principals. No matter how careful any individual is, her privacy will only be as secure as her least competent confidant. Prior approaches to similar problems either rely on new programming language features, making them incompatible with legacy code or track “tainted” within a running process, leading to prohibitively poor performance. Thus, we are exploring a new approach to preventing leaks due to access control misconfigurations through a privacy management system called TightLip. TightLip helps users define what data is important and who is trusted, rather than forcing them to understand the com-

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

TightLip: Keeping Applications from Spilling the Beans

Access control misconfigurations are widespread and can result in damaging breaches of confidentiality. This paper presents TightLip, a privacy management system that helps users define what data is sensitive and who is trusted to see it rather than forcing them to understand or predict how the interactions of their software packages

متن کامل

Clustering and Information Sharing in an Ecology of Cooperating Agents or How to Gossip without Spilling the Beans

Many future applications for advanced software agents imply distributed computation involving sensitive or private data. Most efforts to date have assumed that privacy may be traded away in order to distribute the computation, or assume that the only viable choices for users are to entrust their data completely to a third party, or not at all. This research, still very much in progress, is inte...

متن کامل

Reaching Your Goals without Spilling the Beans: Boolean Secrecy Games

Inspired by the work on Boolean games, we present turnbased games where each of the players controls a set of atomic variables and each player wants to achieve some individual goal in such a way that the other players remain unaware of the goal until it is actually achieved. We present definitions of winning such games with hidden goals for different non-cooperative settings, and discuss in whi...

متن کامل

کاربرد باقلا در جیره طیور گوشتی و راههای کاهش اثر بازدارنده تریپسین آن

A total of adult leghorn roosters and 360 day-old broiler chicks were used in two completely randomized experiment to evaluate metabolizable energy (ME) and feeding value of faba beans in broiler rations. In a factorial arrangement with 10 treatments and 3 replicates chicks were fed isonitrogenous rations containing either 0, 10, 20 or 30 percent of raw, cooked or dehulled faba beans for 8 week...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006