Lune

CCS2025

Enabling Secure and Efficient Data Loss Prevention with a Retention-aware Versioning SSD

Weidong Zhu, Carson Stillman, Sara Rampazzi, Kevin R. B. Butler

2025Year
1Citations

Abstract

Enterprises have always needed to protect and safeguard their intellectual property and proprietary information. Whether it was how to build a better mouse trap, or for brand new marketing model, or the next generation of must-have items, enterprises fighting against competition, data theft or anyone else who would want to steal the idea for themselves. When everything was on paper or on disks of an Enterprise, sensitive data could be secured in a secure physical facility, and safeguarding this information was much easier. With the advent of the computer networks, enterprises adapted computer perimeter security using firewalls, but still the location of the data was housed in an enterprise owned and controlled facility. Due to the digital transformation, this information can now be shifted from the enterprise via many electronic methods. Threat actors no longer need access to the physical data. Email, file transfers, digital collaboration, and social media now allow information to be exchanged remotely. More recently, enterprises are required to protect and safeguard their customer information from uncontrolled access. The National Institute of Standards and Technology (NIST) defines this information as Personally Identifiable Information (PII). Specifically, NIST Special Publication 800-122 defines PII as: "any information about an individual maintained by an agency, including (1) any information that can be used to distinguish or trace an individual's identity, such as name,