Skip to main navigation Skip to search Skip to main content

WatchIT: Who watches your IT guy?

Noam Shalev, Idit Keidar, Yosef Moatti, Yaron Weinsberg

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

System administrators have unlimited access to system resources. As the Snowden case shows, these permissions can be exploited to steal valuable personal, classified, or commercial data. In this work we propose a strategy that increases the organizational information security by constraining IT personnel's view of the system and monitoring their actions. To this end, we introduce the abstraction of perforated containers - while regular Linux containers are too restrictive to be used by system administrators, by "punching holes" in them, we strike a balance between information security and required administrative needs. Our system predicts which system resources should be accessible for handling each IT issue, creates a perforated container with the corresponding isolation, and deploys it in the corresponding machines as needed for fixing the problem. Under this approach, the system administrator retains his superuser privileges, while he can only operate within the container limits. We further provide means for the administrator to bypass the isolation, and perform operations beyond her boundaries. However, such operations are monitored and logged for later analysis and anomaly detection. We provide a proof-of-concept implementation of our strategy, along with a case study on the IT database of IBM Research in Israel.

Original languageEnglish
Title of host publicationMIST 2016 - Proceedings of the International Workshop on Managing Insider Security Threats, co-located with CCS 2016
Pages93-96
Number of pages4
ISBN (Electronic)9781450345712
DOIs
StatePublished - 28 Oct 2016
Event8th ACM CCS International Workshop on Managing Insider Security Threats, MIST 2016 - Vienna, Austria
Duration: 28 Oct 2016 → …

Publication series

NameMIST 2016 - Proceedings of the International Workshop on Managing Insider Security Threats, co-located with CCS 2016

Conference

Conference8th ACM CCS International Workshop on Managing Insider Security Threats, MIST 2016
Country/TerritoryAustria
CityVienna
Period28/10/16 → …

All Science Journal Classification (ASJC) codes

  • Information Systems
  • Computer Science Applications

Fingerprint

Dive into the research topics of 'WatchIT: Who watches your IT guy?'. Together they form a unique fingerprint.

Cite this