Logo image
Working Set-Based Access Control for Network File Systems
Technical documentation   Open access

Working Set-Based Access Control for Network File Systems

Stephen Smaldone, Vinod Ganapathy and Liviu Iftode
Rutgers University
2008
DOI:
https://doi.org/10.7282/T3BR8WK6

Abstract

Securing access to files is an important and growing concern in corporate environments. Employees are increasingly accessing files from untrusted devices, including personal home computers and mobile devices, such as smart phones, that are not under the control of the corporation, and may be infected with viruses, worms, and other malware. In such cases, it is crucial to protect the confidentiality and integrity of corporate data from malicious accesses. Existing tools available to network administrators are either too permissive or too restrictive in allowing file access from untrusted devices. This paper proposes a novel scheme called Working Set-Based Access Control (WSBAC) to restrict network file system accesses from untrusted devices. The key idea is to continuously observe and extract working sets for users when they access files from trusted devices. These working sets are used to restrict file accesses when users connect from untrusted devices. This paper reports on the design and implementation of tools to automatically extract working sets, and transparently enforce WSBAC without requiring changes to the file system. Our experiments with realistic network file system traces lead us to conclude that using working sets offers a flexible yet secure way to restrict access from untrusted devices, and that the runtime overheads of WSBAC enforcement are negligible.
pdf
Working Set-Based Access Control for Network File Systems516.10 kBDownloadView
Version of Record (VoR) Open Access
url
Report an accessibility issueView
Please complete a content remediation request to report an accessibility issue with a library electronic resource, website, or service.

Metrics

173 File downloads
80 Record Views

Details

Logo image