WatchIT: Who Watches Your IT Guy?

被引:2
|
作者
Shalev, Noam [1 ]
Keidar, Idit [1 ]
Moatti, Yosef [2 ]
Weinsberg, Yaron [2 ]
机构
[1] Technion Israel Inst Technol, IL-32000 Haifa, Israel
[2] IBM Res, Haifa, Israel
关键词
D O I
10.1145/2995959.2995968
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
System administrators have unlimited access to system resources. As the Snowden case shows, these permissions can be exploited to steal valuable personal, classified, or commercial data. In this work we propose a strategy that increases the organizational information security by constraining IT personnel's view of the system and monitoring their actions. To this end, we introduce the abstraction of perforated containers while regular Linux containers are too restrictive to be used by system administrators, by "punching holes" in them, we strike a balance between information security and required administrative needs. Our system predicts which system resources should be accessible for handling each IT issue, creates a perforated container with the corresponding isolation, and deploys it in the corresponding machines as needed for fixing the problem. Under this approach, the system administrator retains his superuser privileges, while he can only operate within the container limits. We further provide means for the administrator to bypass the isolation, and perform operations beyond her boundaries. However, such operations are monitored and logged for later analysis and anomaly detection. We provide a proof-of-concept implementation of our strategy, along with a case study on the IT database of IBM Research in Israel.
引用
收藏
页码:93 / 96
页数:4
相关论文
共 50 条
  • [41] Who Watches the Watchers? IT security and safety systems
    Speth, Walter
    Thiel, Christoph
    Winkel, Detlef
    ATP EDITION, 2015, (04): : 48 - 54
  • [42] Who watches the watches: on the delivery of the specifications of smart wearable devices and recommendations on the related best practices
    Simon, Aniko
    Szy, Laszlo
    Kara, Peter A.
    Guindy, Mary
    SMART BIOMEDICAL AND PHYSIOLOGICAL SENSOR TECHNOLOGY XIX, 2022, 12123
  • [43] Who watches the watchmen?: Ideology and "real world" superheroes
    Hughes, Jamie A.
    JOURNAL OF POPULAR CULTURE, 2006, 39 (04): : 546 - 557
  • [44] So who was this Reynolds guy, anyway?
    Gresham, RM
    LUBRICATION ENGINEERING, 2002, 58 (12): : 7 - 8
  • [45] Some Guy Who Kills People
    Dawson, Thomas
    SIGHT AND SOUND, 2012, 22 (12): : 105 - 105
  • [46] Who watches the watchmen? Evaluating evaluations of El Sistema
    Baker, Geoffrey
    Bull, Anna
    Taylor, Mark
    BRITISH JOURNAL OF MUSIC EDUCATION, 2018, 35 (03) : 255 - 269
  • [47] Who's this 'Craig' guy, anyway?
    Saba, Jennifer
    Editor and Publisher, 2005, 138 (07):
  • [48] Who was that big-haired guy?
    Macpherson, E
    NATION, 2004, 278 (08) : 2 - 2
  • [49] Forget your desire: The cinema of Guy Maddin
    White, Kenneth
    MILLENNIUM FILM JOURNAL, 2006, (45-46): : 133 - 139
  • [50] Who watches the watchmen and the problem of recursive flea bites
    Sneyd, J. R.
    BRITISH JOURNAL OF ANAESTHESIA, 2019, 122 (04) : 407 - 408