Title
POSTER: Hidden in Plain Sight: A Filesystem for Data Integrity and Confidentiality.
Abstract
A filesystem capable of curtailing data theft and ensuring file integrity protection through deception is introduced and evaluated. The deceptive filesystem transparently creates multiple levels of stacking to protect the base filesystem and monitor file accesses, hide and redact sensitive files with baits, and inject decoys onto fake system views purveyed to untrusted subjects, all while maintaining a pristine state to legitimate processes. Our prototype implementation leverages a kernel hot-patch to seamlessly integrate the new filesystem module into live and existing environments. We demonstrate the utility of our approach with a use case on the nefarious Erebus ransomware. We also show that the filesystem adds no I/O overhead for legitimate users.
Year
DOI
Venue
2017
10.1145/3133956.3138841
CCS
Keywords
Field
DocType
Intrusion Detection and Prevention, Cyber Deception, Filesystems
Internet privacy,Intrusion detection and prevention,Ransomware,Confidentiality,Computer science,Computer security,Deception,Sight,Data integrity,Data theft
Conference
ISBN
Citations 
PageRank 
978-1-4503-4946-8
1
0.41
References 
Authors
3
4
Name
Order
Citations
PageRank
Anne Kohlbrenner121.16
Frederico Araujo2396.65
Teryl Taylor3304.87
Marc Ph. Stoecklin416615.05