• DocumentCode
    2103875
  • Title

    Privacy-aware: Tracking and protecting sensitive information using automatic type inference

  • Author

    Ouyang, Weiwei

  • Author_Institution
    Enterprise Data Manage., State Street Technol. (Zhejiang) Co., Ltd., Hangzhou, China
  • fYear
    2010
  • fDate
    17-19 Dec. 2010
  • Firstpage
    665
  • Lastpage
    668
  • Abstract
    It is very hard to ensure that software is free of sensitive information leaks because current common software takes very little measures to control sensitive data propagation or limit data lifetime. We present Privacy-Aware, a sensitive data tracker and eraser based on type qualifier inference. We have adapted a simplified type qualifier inference to the LLVM framework, a low-level virtual machine infrastructure for a batch of languages. With type qualifier inference, Privacy-Aware can automatically reason about where the sensitive data has been propagated to and erase them before deallocation. We optimize Privacy-Aware with alias analysis and points-to analysis so that Privacy-Aware can be used as an effective annotation system for programmer to reduce the data lifetime in software development with minimal annotation effort. We have implemented Privacy-Aware by LLVM-based instrumentation. The preliminary evaluation suggests that Privacy-Aware can effectively clear sensitive data while only incurring a small amount of overhead, on average below 10%, in our benchmark. Our research provides evidence that requiring minimal programmer intervention, Privacy-Aware is an effective, efficient and autonomous strategy in privacy protection.
  • Keywords
    data privacy; security of data; software engineering; virtual machines; LLVM framework; alias analysis; automatic type inference; effective annotation system; low-level virtual machine infrastructure; minimal programmer intervention; points-to analysis; privacy-aware; sensitive data eraser; sensitive data tracker; sensitive information protection; sensitive information tracking; software development; type qualifier inference; Instruments; Kernel; Optimization; Privacy; Resource management; Security; privacy protection; secure deallocation; taint analysis; type qualifier;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Theory and Information Security (ICITIS), 2010 IEEE International Conference on
  • Conference_Location
    Beijing
  • Print_ISBN
    978-1-4244-6942-0
  • Type

    conf

  • DOI
    10.1109/ICITIS.2010.5689484
  • Filename
    5689484