BrowserFlow: imprecise data flow tracking to prevent accidental data disclosure
File(s) browserflow-middleware16.pdf (1.34 MB)
Accepted version
Author(s)
Papagiannis, I
Watcharapichat, P
Muthukumaran, D
Pietzuch, PR
Type
Conference Paper
Abstract
With the use of external cloud services such as Google Docs or Evernote in an enterprise setting, the loss of control over sensitive data becomes a major concern for organisations. It is typical for regular users to violate data disclosure policies accidentally, e.g. when sharing text between documents in browser tabs. Our goal is to help such users comply with data disclosure policies: we want to alert them about potentially unauthorised data disclosure from trusted to untrusted cloud services. This is particularly challenging when users can modify data in arbitrary ways, they employ multiple cloud services, and cloud services cannot be changed.
To track the propagation of text data robustly across cloud services, we introduce imprecise data flow tracking, which identifies data flows implicitly by detecting and quantifying the similarity between text fragments. To reason about violations of data disclosure policies, we describe a new text disclosure model that, based on similarity, associates text fragments in web browsers with security tags and identifies unauthorised data flows to untrusted services. We demonstrate the applicability of imprecise data tracking through BrowserFlow, a browser-based middleware that alerts users when they expose potentially sensitive text to an untrusted cloud service. Our experiments show that BrowserFlow can robustly track data flows and manage security tags for documents with no noticeable performance impact.
To track the propagation of text data robustly across cloud services, we introduce imprecise data flow tracking, which identifies data flows implicitly by detecting and quantifying the similarity between text fragments. To reason about violations of data disclosure policies, we describe a new text disclosure model that, based on similarity, associates text fragments in web browsers with security tags and identifies unauthorised data flows to untrusted services. We demonstrate the applicability of imprecise data tracking through BrowserFlow, a browser-based middleware that alerts users when they expose potentially sensitive text to an untrusted cloud service. Our experiments show that BrowserFlow can robustly track data flows and manage security tags for documents with no noticeable performance impact.
Date Issued
2016-11-01
Date Acceptance
2016-09-09
Citation
Middleware '16: 17th International Middleware Conference, 2016, pp.1-13
Publisher
ACM
Start Page
1
End Page
13
Journal / Book Title
Middleware '16: 17th International Middleware Conference
Copyright Statement
© 2016 Copyright held by the owner/author(s). Publication rights licensed to ACM. This is the author's version of the work. It is posted here by permission of ACM for your personal use. Not for redistribution. The definitive version was published in Middleware '16: 17th International Middleware Conference (Nov 2016), https://dl.acm.org/doi/abs/10.1145/2988336.2988345
Sponsor
Engineering & Physical Science Research Council (EPSRC)
Grant Number
EP/J020370/1
Source
Middleware '16: 17th International Middleware Conference
Publication Status
Published
Start Date
2016-12-12
Finish Date
2016-12-16
Coverage Spatial
Trento, Italy
