• DocumentCode
    623892
  • Title

    Protecting cloud data using dynamic inline fingerprint checks

  • Author

    Fang Hao ; Kodialam, Murali ; Lakshman, T.V. ; Puttaswamy, Krishna P. N.

  • Author_Institution
    Bell Labs., Alcatel-Lucent, Holmdel, NJ, USA
  • fYear
    2013
  • fDate
    14-19 April 2013
  • Firstpage
    2877
  • Lastpage
    2885
  • Abstract
    Preventing flow of confidential data out of a network is a fundamental problem faced by network operators. This problem gets even more complex in the context of Cloud Computing, where multiple distrusting customers share the same underlying infrastructure, and data is often replicated and moved across regions. Despite the significance of this problem, existing solutions are based on generic search for keywords in outgoing data, and hence severely lack the ability to control data flow at a fine granularity with low false positives. In this paper, we advocate a fine-grained approach to prevent confidential data from leaking out of the cloud. We propose a solution using document-level fingerprint checks. We show via analysis and experiments that our algorithm for checking the fingerprints on-the-fly scale to a large amount of documents at very low cost. For example, for one TB of documents, our solution only requires 340 MB memory to achieve worst case expected detection lag (i.e. leakage length) of 1000 bytes.
  • Keywords
    cloud computing; document handling; security of data; cloud computing; cloud data protection; confidential data flow; document-level fingerprint checks; dynamic inline fingerprint checks; fingerprint on-the-fly scale checking; keyword generic search; worst case expected detection lag; Algorithm design and analysis; Databases; Equations; Heuristic algorithms; Memory management; Probabilistic logic; Protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM, 2013 Proceedings IEEE
  • Conference_Location
    Turin
  • ISSN
    0743-166X
  • Print_ISBN
    978-1-4673-5944-3
  • Type

    conf

  • DOI
    10.1109/INFCOM.2013.6567098
  • Filename
    6567098