USENIX Security2016Top-tier venue
Thoth: Comprehensive Policy Compliance in Data Retrieval Systems
Eslam Elnikety, Aastha Mehta, Anjo Vahldiek-Oberwagner, Deepak Garg, Peter Druschel
Abstract
Data retrieval systems process data from many sources, each subject to its own data use policy. Ensuring compliance with these policies despite bugs, misconfiguration, or operator error in a large, complex, and fast evolving system is a major challenge. Thoth provides an efficient, kernel-level compliance layer for data use policies. Declarative policies are attached to the systems' input and output files, key-value tuples, and network connections, and specify the data's integrity and confidentiality requirements. Thoth tracks the flow of data through the system, and enforces policy regardless of bugs, misconfigurations, compromises in application code, or actions by unprivileged operators. Thoth requires minimal changes to an existing system and has modest overhead, as we show using a prototype Thoth-enabled data retrieval system based on the popular Apache Lucene.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext be2ddea9-8136-4f3e-b3f9-186d0e4e0269Cited by top-tier papers10
- Zeph: Cryptographic Enforcement of End-to-End Data PrivacyLukas Burkhalter, Nicolas Küchler, Alexander Viand, Hossein Shafagh et al.OSDI 2021 · 35 citations
- GRASP: Hardening Serverless Applications through Graph Reachability Analysis of Security PoliciesIsaac Polinsky, Pubali Datta, Adam Bates, William EnckWWW 2024 · 15 citations
- Vizard: A Metadata-hiding Data Analytic System with End-to-End Policy ControlsChengjun Cai, Yichen Zang, Cong Wang, Xiaohua Jia et al.CCS 2022 · 12 citations
- Perennial Semantic Data Terms of Use for Decentralized WebRui Zhao, Jun ZhaoWWW 2024 · 9 citations
- Hammurabi: A Framework for Pluggable, Logic-Based X.509 Certificate Validation PoliciesJames Larisch, Waqar Aqeel, Michael Lum, Yaelle Goldschlag et al.CCS 2022 · 8 citations
Related papers
- Qapla: Policy compliance for database-backed systemsAastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg et al.USENIX Security 2017 · 46 citations
- Data Guard: A Fine-Grained Purpose-Based Access Control System for Large Data WarehousesKhai Tran, Sudarshan Vasudevan, Pratham Desai, Alex Gorelik et al.ICDE 2026
- Extracting Database Access-Control Policies from Web ApplicationsWen Zhang, Dev Bali, Jamison Kerney, Aurojit Panda et al.OSDI 2026
- Cryptographically Secure Information Flow Control on Key-Value StoresLucas Waye, Pablo Buiras, Owen Arden, Alejandro Russo et al.CCS 2017 · 8 citations
- Software-Defined Data Protection: Low Overhead Policy Compliance at the Storage Layer is Within Reach!Zsolt István, Soujanya Ponnapalli, Vijay ChidambaramVLDB 2021 · 19 citations
