Tightlip: keeping applications from spilling the beans
Aydan R. Yumerefendi, Benjamin Mickle, Landon P. Cox · 2007
Access control misconfigurations are widespread and can result in damaging breaches of confidentiality. This paper presents TightLip, a privacy management system that helps users define what data is sensitive and who is trusted to see it rather than forcing them to understand or predict how the interactions of their software packages can leak data. The key mechanism used by TightLip to detect and prevent breaches is the doppelganger process. Doppelgangers are sandboxed copy processes that inherit most, but not all, of the state of an original process. The operating system runs a doppelganger and its original in parallel and uses divergent process outputs to detect potential privacy leaks. TightLip is compatible with legacy-code and provides complete, continuous protection at a modest performance cost. SpecWeb99 results show that Apache running on the TightLip prototype exhibits a negligible 5% slowdown in request rate, response time, and transfer rate compared to an unmodified server environment. 1