{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:28:10Z","timestamp":1750307290982,"version":"3.41.0"},"reference-count":33,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2011,5,1]],"date-time":"2011-05-01T00:00:00Z","timestamp":1304208000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000143","name":"Division of Computing and Communication Foundations","doi-asserted-by":"publisher","award":["CCF-0846195CCF-0725350"],"award-info":[{"award-number":["CCF-0846195CCF-0725350"]}],"id":[{"id":"10.13039\/100000143","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2011,5]]},"abstract":"<jats:p>We present a new technique that can trace data provenance and enforce data access policies across multiple applications and machines. We have developed Garm, a tool that uses binary rewriting to implement this technique on arbitrary binaries. Users can use Garm to attach access policies to data and Garm enforces the policy on all accesses to the data (and any derived data) across all applications and executions. Garm uses static analysis to generate optimized instrumentation that traces the provenance of an application's state and the policies that apply to this state. Garm monitors the interactions of the application with the underlying operating system to enforce policies. Conceptually, Garm combines trusted computing support from the underlying operating system with a stream cipher to ensure that data protected by an access policy cannot be accessed outside of Garm's policy enforcement mechanisms. We have evaluated Garm with several common Linux applications. We found that Garm can successfully trace the provenance of data across executions of multiple applications and enforce data access policies on the application's executions.<\/jats:p>","DOI":"10.1145\/1952982.1952988","type":"journal-article","created":{"date-parts":[[2011,6,6]],"date-time":"2011-06-06T11:51:38Z","timestamp":1307361098000},"page":"1-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Cross-application data provenance and policy enforcement"],"prefix":"10.1145","volume":"14","author":[{"given":"Brian","family":"Demsky","sequence":"first","affiliation":[{"name":"University of California, Irvine, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2011,6,6]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-68351-3_8"},{"volume-title":"Proceedings of the 20th Conference on the Foundations of Software Technology and Theoretical Computer Science.","author":"Buneman P.","key":"e_1_2_1_2_1"},{"volume-title":"Proceedings of the 8th International Conference on Database Theory.","author":"Buneman P.","key":"e_1_2_1_3_1"},{"volume-title":"Proceedings of the 23rd Annual Computer Security Applications Conference.","author":"Chandra D.","key":"e_1_2_1_4_1"},{"volume-title":"Proceedings of the 13th USENIX Conference on Security.","author":"Chow J.","key":"e_1_2_1_5_1"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1273463.1273490"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250662.1250722"},{"volume-title":"Proceedings of the USENIX Workshop on Hot Topics in Security (HotSec).","year":"2009","author":"Demsky B.","key":"e_1_2_1_8_1"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/360051.360056"},{"volume-title":"Proceedings of the 1st USENIX Workshop on Offensive Technologies.","author":"Drewry W.","key":"e_1_2_1_10_1"},{"key":"e_1_2_1_11_1","unstructured":"ecrypt. 2008. The eSTREAM project. http:\/\/www.ecrypt.eu.org\/stream\/.  ecrypt. 2008. The eSTREAM project. http:\/\/www.ecrypt.eu.org\/stream\/."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.41"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2003.1212691"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.21"},{"volume-title":"Proccedings of the 7th Conference on File and Storage Technologies.","author":"Hasan R.","key":"e_1_2_1_15_1"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.30"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.35"},{"volume-title":"Proceedings of the 12th European Symposium on Research in Computer Security.","author":"Hilty M.","key":"e_1_2_1_18_1"},{"key":"e_1_2_1_19_1","unstructured":"Iannela R. 2002. Open digital rights language\u2014version 1.1. http:\/\/ordl.net\/1.1\/ODRL-11.pdf.  Iannela R. 2002. Open digital rights language\u2014version 1.1. http:\/\/ordl.net\/1.1\/ODRL-11.pdf."},{"volume-title":"Proceedings of the 38th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks.","author":"Lin Z.","key":"e_1_2_1_20_1"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1375581.1375606"},{"key":"e_1_2_1_22_1","doi-asserted-by":"crossref","unstructured":"Mitchell C. 2005. Trusted Computing. Institution of Engineering and Technology Stevenage; Herts U.K.  Mitchell C. 2005. Trusted Computing. Institution of Engineering and Technology Stevenage; Herts U.K.","DOI":"10.1049\/PBPC006E_ch1"},{"volume-title":"Proceedings of the Annual USENIX Technical Conference.","author":"Muniswamy-Reddy K.-K.","key":"e_1_2_1_23_1"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.entcs.2007.10.010"},{"volume-title":"Proceedings of the Network and Distributed System Security Symposium.","author":"Newsome J.","key":"e_1_2_1_25_1"},{"key":"e_1_2_1_26_1","series-title":"Lecture Notes in Computer Science","volume-title":"NGSCB: A Trusted Open System","author":"Peinado M.","year":"2004"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1368310.1368344"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2002.806121"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2004.31"},{"volume-title":"Proceedings of the USENIX Workshop on Hot Topics in Security (HotSec).","author":"Wurster G.","key":"e_1_2_1_30_1"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315261"},{"volume-title":"Proceedings of the 7th USENIX Symposium on Operating Systems Design and Implementation.","author":"Zeldovich N.","key":"e_1_2_1_32_1"},{"volume-title":"Proceedings of the 5th USENIX Symposium on Networked Systems Design and Implementation.","author":"Zeldovich N.","key":"e_1_2_1_33_1"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1952982.1952988","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1952982.1952988","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:59:41Z","timestamp":1750244381000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1952982.1952988"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,5]]},"references-count":33,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2011,5]]}},"alternative-id":["10.1145\/1952982.1952988"],"URL":"https:\/\/doi.org\/10.1145\/1952982.1952988","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"type":"print","value":"1094-9224"},{"type":"electronic","value":"1557-7406"}],"subject":[],"published":{"date-parts":[[2011,5]]},"assertion":[{"value":"2009-09-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2010-04-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-06-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}