Visible to the public Using VisorFlow to Control Information Flow Without Modifying the Operating System Kernel or Its Userspace

TitleUsing VisorFlow to Control Information Flow Without Modifying the Operating System Kernel or Its Userspace
Publication TypeConference Paper
Year of Publication2017
AuthorsShockley, Matt, Maixner, Chris, Johnson, Ryan, DeRidder, Mitch, Petullo, W. Michael
Conference NameProceedings of the 2017 International Workshop on Managing Insider Security Threats
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-5177-5
Keywordscomposability, Information Flow Control, Metrics, pubcrawl, resilience, Resiliency, security, virtual-machine introspection, Windows operating system
Abstract

VisorFlow aims to monitor the flow of information between processes without requiring modifications to the operating system kernel or its userspace. VisorFlow runs in a privileged Xen domain and monitors the system calls executing in other domains running either Linux or Windows. VisorFlow uses its observations to prevent confidential information from leaving a local network. We describe the design and implementation of VisorFlow, describe how we used VisorFlow to confine na\"ive users and malicious insiders during the 2017 Cyber-Defense Exercise, and provide performance measurements. We have released VisorFlow and its companion library, libguestrace, as open-source software.

URLhttps://dl.acm.org/citation.cfm?doid=3139923.3139924
DOI10.1145/3139923.3139924
Citation Keyshockley_using_2017