GLOBAL VIRTUAL VAULT: PREVENTING UNAUTHORIZED PHYSICAL DISCLOSURE BY THE INSIDER

被引:0
作者
Fisk, Mike [1 ]
Miller, Scott [1 ]
Kent, Alex [1 ]
机构
[1] Los Alamos Natl Lab, Los Alamos, NM 87545 USA
来源
2008 IEEE MILITARY COMMUNICATIONS CONFERENCE: MILCOM 2008, VOLS 1-7 | 2008年
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Information providers on networks such as the Global Information Grid need to share sensitive information while still protecting that information from misuse. We show how common information-sharing mechanisms encourage and allow high-bandwidth, hard-to-detect information ex-filtration by malicious insiders, and by adversaries in the field. By leveraging netcentricity, modern stateless clients, and advances in distance visualization techniques, we can provide analysts and warfighters with highly-usable access to information that remains secured in high-availability, high-security data centers. We quantitatively analyze the intentional mid inadvertent data exfiltration paths of several off-the-shelf secure computing solutions and demonstrate how to re-engineer these systems to greatly reduce residual risk by limiting access to human-interaction protocols. This approach eliminates large classes of insider attacks that are largely unaddressed in most systems and concentrates traditional insider access to manageable, well-defended physical security perimeters.
引用
收藏
页码:1192 / 1198
页数:7
相关论文
共 21 条
[1]  
[Anonymous], 2006, HIT BUS PHYS ACCESS
[2]  
BAKER CW, 2008, 2008 DATA BREACH INV
[3]  
BOSWORTH MH, 2007, EMORY HEALTHCARE LAP
[4]  
CARR J, 2007, SC MAGAZINE JUL
[5]  
Carrier Brian D, 2004, Digit. Investig, V1, P50, DOI [DOI 10.1016/J.DIIN.2003.12.001, 10.1016/j.diin.2003.12.001]
[6]  
*CISC SYST, 2008, CAT 6500 SER SWITCH
[7]  
*DIG DISPL WORK GR, 1999, DIG VID INT
[8]  
DODGE A, 2008, ED SECURITY INCIDENT
[9]  
DORNSEIF M, 2004, OWNED IPOD
[10]  
FILES J, 2006, NY TIMES JUN