DocumentCode :
2777122
Title :
Accessing Trusted Web Sites from Low-Integrity Systems without End-Host Snooping
Author :
Lau, Billy ; Prakash, Atul ; Annamalai, Venkatanathan
Author_Institution :
Univ. of Michigan, Ann Arbor, MI, USA
fYear :
2011
fDate :
9-11 Oct. 2011
Firstpage :
1012
Lastpage :
1019
Abstract :
The weakest link in secure web site access is often the end-host. Any malicious software installed there, or a runtime browser compromise, can lead to theft of critical information which is stored locally. Today´s state-of-the-art in host-based intrusion detection and prevention systems has not succeeded in eradicating this problem. In this paper, we introduce an orthogonal solution: a system that guarantees the confidentiality of sensitive documents produced during web transactions, even on a compromised browser or operating system. Compared to other solutions that utilizes virtual machines, our approach does not require user to run multiple guests and switch between them. Rather, to get the guarantees, users can switch the mode of operation of its current system to custom-defined compartments when necessary. Documents created in specific compartment will only be accessible within that compartment and can only flow between the authorized sites stated in the corresponding compartment policy. The system only requires a trusted hyper visor within which the user´s low-integrity OS runs as a guest. We describe the architecture of the system, a prototype implementation, and the modifications to the hyper visor to make transitions into and out of secure compartment(s) fast enough for interactive use.
Keywords :
Web sites; authorisation; data integrity; document handling; online front-ends; operating systems (computers); trusted computing; virtual machines; Web transaction; authorized site; compartment policy; custom-defined compartment; end-host snooping; host-based intrusion detection; low integrity OS; low integrity system; malicious software; operating system; prevention system; run-time browser compromise; secure Web site access; secure compartment; trusted Web site; trusted hypervisor; virtual machine; Cloning; Linux; Malware; Software; Switches; Virtual machine monitors; Web sites;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Privacy, Security, Risk and Trust (PASSAT) and 2011 IEEE Third Inernational Conference on Social Computing (SocialCom), 2011 IEEE Third International Conference on
Conference_Location :
Boston, MA
Print_ISBN :
978-1-4577-1931-8
Type :
conf
DOI :
10.1109/PASSAT/SocialCom.2011.162
Filename :
6113253
Link To Document :
بازگشت