MultiFile View: File-View-Based Isolation in a Single-User Environment to Protect User Data Files
Jione Choi, Junghee Lee, Gyuho Lee, Jaegwan Yu, Aran Park, Chrysostomos A. Nicopoulos · IEEE Transactions on Dependable and Secure Computing · 2025
Isolation technology is often used to reduce the impact of cyber attacks, and it is mainly used in multi-user environments. Representative examples of said technology include access-control mechanisms and virtual machines. In a single-user environment, virtual addressing and a trusted execution environment isolate applications. However, the focus of such techniques is usually only on isolation, while the sharing of files has not been given much attention. In a single-user environment, users have the ability to access the same file through multiple applications. In this paper, we introduce the concept offile view, and propose file isolation based on the notion ofviews. Under the proposedMultiFile Viewmechanism, files within a view can be accessed by multiple applications when that particular view is activated. In other words, files appear only if their associated view is activated. The proposed technique is effective in protecting files from attacks on user data files, such as ransomware, wiper, and evil maid attacks. We also develop three models to describe how to assign views to applications. The proposed technique is prototyped in Windows 10. Through extensive experiments, we demonstrate that the new technique’s performance overhead does not noticeably affect the overall user experience.