Abstract
Making vital disk data recoverable even in the event of OS compromises has become a necessity, in view of the increased prevalence of OS vulnerability exploits over the recent years. We present the design and implementation of a secure disk system, SVSDS, that performs selective, flexible, and transparent versioning of stored data, at the disk-level. In addition to versioning, SVSDS actively enforces constraints to protect executables and system log files. Most existing versioning solutions that operate at the disk-level are unaware of the higher-level abstractions of data, and hence are not customizable. We evolve a hybrid solution that combines the advantages of disk-level and file-system—level versioning systems thereby ensuring security, while at the same time allowing flexible policies. We implemented and evaluated a software-level prototype of SVSDS in the Linux kernel and it shows that the space and performance overheads associated with selective versioning at the disk level are minimal.
| Original language | English |
|---|---|
| Pages | 259-274 |
| Number of pages | 16 |
| State | Published - 2008 |
| Event | 17th USENIX Security Symposium, USENIX Security 2008 - San Jose, United States Duration: Jul 28 2008 → Aug 1 2008 |
Conference
| Conference | 17th USENIX Security Symposium, USENIX Security 2008 |
|---|---|
| Country/Territory | United States |
| City | San Jose |
| Period | 07/28/08 → 08/1/08 |
Fingerprint
Dive into the research topics of 'Selective versioning in a secure disk system'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver