{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,22]],"date-time":"2026-05-22T09:08:44Z","timestamp":1779440924637,"version":"3.53.1"},"reference-count":49,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2026,5,22]],"date-time":"2026-05-22T00:00:00Z","timestamp":1779408000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Italian National hub Enabling and Enhancing networked applications and Services for digitally Transforming SMEs and Public Administrations","award":["G.A. 101083398\u2014CUP F63C22000980006"],"award-info":[{"award-number":["G.A. 101083398\u2014CUP F63C22000980006"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>\n                    High-privilege insiders, such as IT administrators, pose a significant threat to data integrity, whether through accidental errors or malicious intent. Unauthorized modifications or deletions of critical data\u2014such as system logs and access records\u2014can cause severe operational and security disruptions. Traditionally, these threats are mitigated using hardware-based solutions such as Write-Once Read-Many (WORM) storage. While effective, these approaches have notable drawbacks, including high deployment costs and irreversible consumption of storage blocks, which cannot be reused once written. The goal of this article is to explore purely software-based solutions to these challenges. To this end, we design VaultFS, a software-only file system for Linux environments tailored for the protection of cold data\u2014data that must remain accessible but unmodifiable. VaultFS enables writing through a standard file system interface while ensuring strict immutability and undeletability for a pre-defined time window, potentially infinite. Even threads operating with (effective)root-id permissions cannot alter or remove stored data, preserving integrity against privilege escalation threats. Achieving this requires addressing a number of key technical challenges, such as ensuring a trusted time reference to enforce temporal protection guarantees, and forcing a suited admission control policy to avoid any interaction with the file system that could be potentially dangerous, including access to the file system block device via common services offered by the Linux virtual file system. Furthermore, VaulFS mitigates storage-exhaustion Denial-of-Service (DoS) attacks, where untrusted applications flood the file system with non-removable content. We evaluate the integration of VaultFS with practical applications, demonstrating full compatibility with all seven backup tools assessed\u2014including\n                    <jats:monospace>mysqldump<\/jats:monospace>\n                    and\n                    <jats:monospace>rsynch<\/jats:monospace>\n                    \u2014and seamless integration with most of the video surveillance applications tested\u2014including\n                    <jats:monospace>ivideon<\/jats:monospace>\n                    and\n                    <jats:monospace>ZoneMinder<\/jats:monospace>\n                    . Furthermore, our experimental evaluation shows that VaultFS incurs only a 7\u201312% performance overhead compared to the common Linux Ext4 file system under the usage of read\/write intensive applications performing file-copy operations.\n                  <\/jats:p>","DOI":"10.1145\/3797891","type":"journal-article","created":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T14:07:38Z","timestamp":1779286058000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["VaultFS: Data Integrity via Write-Once Software Support at the File System Level"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-0552-7894","authenticated-orcid":false,"given":"Pasquale","family":"Caporaso","sequence":"first","affiliation":[{"name":"Dipartimento di Ingegneria Civile e Ingegneria Informatica, University of Rome Tor Vergata, Rome, Italy and Network Assessment Assurance and Monitoring Laboratory, Consorzio Nazionale Interuniversitario per le Telecomunicazioni, Parma, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7277-7423","authenticated-orcid":false,"given":"Giuseppe","family":"Bianchi","sequence":"additional","affiliation":[{"name":"University of Rome Tor Vergata, Rome, Italy and Network Assessment Assurance and Monitoring Laboratory, Consorzio Nazionale Interuniversitario per le Telecomunicazioni, Parma, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5616-7980","authenticated-orcid":false,"given":"Francesco","family":"Quaglia","sequence":"additional","affiliation":[{"name":"Dipartimento di Ingegneria Civile e Ingegneria Informatica, University of Rome Tor Vergata, Roma, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,5,22]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"Cisco Press. 2026. Building Blocks for Data Center Cloud Architectures. Retrieved from https:\/\/www.ciscopress.com\/articles\/article.asp?p=2273594&seqNum=4"},{"key":"e_1_3_2_3_2","unstructured":"Jeannine Walter Dan Tulledge and NetApp. 2023. Compliant WORM Storage Using NetApp SnapLock. Retrieved from https:\/\/www.netapp.com\/pdf.html?item=\/media\/6158-tr4526pdf.pdf"},{"key":"e_1_3_2_4_2","unstructured":"Jake Edge. 2020. Control-Flow Integrity for the Kernel. Retrieved from https:\/\/lwn.net\/Articles\/810077\/"},{"key":"e_1_3_2_5_2","unstructured":"Kernel Development Community. 2026. CramFS. Retrieved from https:\/\/docs.kernel.org\/filesystems\/cramfs.html"},{"key":"e_1_3_2_6_2","unstructured":"Kees Cook. 2017. Free List Pointer Protection. Retrieved from https:\/\/lists.openwall.net\/linux-kernel\/2017\/07\/07\/546"},{"key":"e_1_3_2_7_2","unstructured":"Jeffrey B. Layton. 2019. Linux Extended File Attributes Tutorial. Retrieved from https:\/\/www.linuxtoday.com\/blog\/linux-extended-file-attributes\/"},{"key":"e_1_3_2_8_2","unstructured":"H. Larry. 2009. Linux Kernel Heap Tampering Detection. Retrieved from https:\/\/phrack.org\/issues\/66\/15"},{"key":"e_1_3_2_9_2","unstructured":"Kernel Development Community. 2026. Linux Kernel ktime accessors. Retrieved from https:\/\/docs.kernel.org\/core-api\/timekeeping.html"},{"key":"e_1_3_2_10_2","unstructured":"Kernel Development Community. 2026. Linux Security Module Usage. Retrieved from https:\/\/www.kernel.org\/doc\/html\/v4.14\/admin-guide\/LSM\/index.html"},{"key":"e_1_3_2_11_2","unstructured":"Robert Sheldon. 2024. An Overview of Microsoft Project Silica and Its Archive Use. Retrieved from https:\/\/www.techtarget.com\/searchstorage\/feature\/An-overview-of-Microsoft-Project-Silica-and-its-archive-use"},{"key":"e_1_3_2_12_2","unstructured":"Intel Corporation. 1999. Preboot Execution Environment (PXE) Specification v2.1. Retrieved from http:\/\/www.pix.net\/software\/pxeboot\/archive\/pxespec.pdf"},{"key":"e_1_3_2_13_2","unstructured":"Ruiqi Gong. 2023. Randomized Slab Caches. Retrieved from https:\/\/lwn.net\/Articles\/938246\/"},{"key":"e_1_3_2_14_2","unstructured":"The seL4 Microkernel. 2026. seL4. Retrieved from https:\/\/sel4.systems\/"},{"key":"e_1_3_2_15_2","unstructured":"Jonathan Corbet. 2018. The Slab and Protected-Memory Allocators. Retrieved from https:\/\/lwn.net\/Articles\/753154\/"},{"key":"e_1_3_2_16_2","unstructured":"Kernel Development Community. 2026. SquashFS. Retrieved from https:\/\/docs.kernel.org\/filesystems\/squashfs.html"},{"key":"e_1_3_2_17_2","unstructured":"Victoria Barrett. 2023. Write-Once-Read-Many (WORM) Tamper Proof Technology. Retrieved from https:\/\/www.nexusindustrialmemory.com\/write-once-read-many\/"},{"key":"e_1_3_2_18_2","first-page":"7141","volume-title":"Proceedings of the 33rd USENIX Security Symposium (USENIX Security \u201924)","author":"Avllazagaj Erin","year":"2024","unstructured":"Erin Avllazagaj, Yonghwi Kwon, and Tudor Dumitras. 2024. SCAVY: Automated discovery of memory corruption targets in Linux Kernel for privilege escalation. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security \u201924). USENIX Association, 7141\u20137158. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/avllazagaj"},{"key":"e_1_3_2_19_2","volume-title":"Proceedings of the 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS)","author":"Baek Sungha","year":"2018","unstructured":"Sungha Baek, Youngdon Jung, Aziz Mohaisen, Sungjin Lee, and Daehun Nyang. 2018. SSD-insider: Internal defense of solid-state drive against ransomware with perfect data recovery. In Proceedings of the 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS). IEEE."},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787905"},{"key":"e_1_3_2_21_2","doi-asserted-by":"crossref","first-page":"336","DOI":"10.1145\/2991079.2991110","volume-title":"Proceedings of the 32nd Annual Conference on Computer Security Applications, (ACSAC \u201916)","author":"Continella Andrea","year":"2016","unstructured":"Andrea Continella, Alessandro Guagnelli, Giovanni Zingaro, Giulio De Pasquale, Alessandro Barenghi, Stefano Zanero, and Federico Maggi. 2016. ShieldFS: A self-healing, ransomware-aware filesystem. In Proceedings of the 32nd Annual Conference on Computer Security Applications, (ACSAC \u201916). Stephen Schwab, William K. Robertson, and Davide Balzarotti (Eds.), ACM, New York, NY, 336\u2013347. Retrieved from http:\/\/dl.acm.org\/citation.cfm?id=2991110"},{"key":"e_1_3_2_22_2","unstructured":"Oracle Corporation. 2008. Welcome to BTRFS Documentation. Retrieved from https:\/\/btrfs.readthedocs.io\/en\/latest\/"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3214781"},{"key":"e_1_3_2_24_2","unstructured":"European Union. 2016. General Data Protection Regulation (GDPR). EU Regulation 2016\/679 on data protection and privacy effective May 2018. Retrieved from https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj"},{"key":"e_1_3_2_25_2","unstructured":"Financial Industry Regulatory Authority. 2025. Financial Industry Regulatory Authority (FINRA). Retrieved from https:\/\/www.finra.orgSelf-regulatory organization for broker-dealers in the United States"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.11.019"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/TETC.2017.2756908"},{"key":"e_1_3_2_28_2","volume-title":"Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security","author":"Huang Jian","year":"2017","unstructured":"Jian Huang, Jun Xu, Xinyu Xing, Peng Liu, and Moinuddin K Qureshi. 2017. FlashGuard. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. ACM, New York, NY, USA."},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134035"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-191346"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00500-018-3257-z"},{"key":"e_1_3_2_32_2","first-page":"757","volume-title":"Proceedings of the 25th USENIX Security Symposium (USENIX Security \u201916)","author":"Kharraz Amin","year":"2016","unstructured":"Amin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson, and Engin Kirda. 2016. UNVEIL: A large-scale, automated approach to detecting ransomware. In Proceedings of the 25th USENIX Security Symposium (USENIX Security \u201916). Thorsten Holz and Stefan Savage (Eds.). USENIX Association, 757\u2013772. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/kharaz"},{"key":"e_1_3_2_33_2","first-page":"98","volume-title":"Proceedings of the 20th International Symposium on Research in Attacks, Intrusions, and Defenses (RAID \u201917)","volume":"10453","author":"Kharraz Amin","year":"2017","unstructured":"Amin Kharraz and Engin Kirda. 2017. Redemption: Real-time protection against ransomware at end-hosts. In Proceedings of the 20th International Symposium on Research in Attacks, Intrusions, and Defenses (RAID \u201917). Marc Dacier, Michael Bailey, Michalis Polychronakis, and Manos Antonakakis (Eds.), Lecture Notes in Computer Science, Vol. 10453, Springer, 98\u2013119. DOI: 10.1007\/978-3-319-66332-6_5"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-20550-2_1"},{"key":"e_1_3_2_35_2","first-page":"599","volume-title":"Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security (ASIA CCS \u201917)","author":"Kolodenker Eugene","year":"2017","unstructured":"Eugene Kolodenker, Wil Koch, Gianluca Stringhini, and Manuel Egele. 2017. PayBreak: Defense against cryptographic ransomware. In Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security (ASIA CCS \u201917), 599\u2013611. DOI: 10.1145\/3052973.3053035"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/LOCS.2019.2918091"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/LES.2020.3035875"},{"key":"e_1_3_2_38_2","first-page":"341","volume-title":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security","author":"Ma Boyang","year":"2023","unstructured":"Boyang Ma, Yilin Yang, Jinku Li, Fengwei Zhang, Wenbo Shen, Yajin Zhou, and Jianfeng Ma. 2023. Travelling the hypervisor and SSD: A tag-based approach against crypto ransomware with fine-grained data recovery. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security. ACM, New York, NY, USA, 341\u2013355."},{"key":"e_1_3_2_39_2","first-page":"114","volume-title":"Proceedings of the 21st International Symposium on Research in Attacks, Intrusions, and Defenses (RAID \u201918)","volume":"11050","author":"Mehnaz Shagufta","year":"2018","unstructured":"Shagufta Mehnaz, Anand Mudgerikar, and Elisa Bertino. 2018. RWGuard: A real-time detection system against cryptographic ransomware. In Proceedings of the 21st International Symposium on Research in Attacks, Intrusions, and Defenses (RAID \u201918). Michael Bailey, Thorsten Holz, Manolis Stamatogiannakis, and Sotiris Ioannidis (Eds.), Lecture Notes in Computer Science, Vol. 11050, Springer, 114\u2013136. DOI: 10.1007\/978-3-030-00470-5_6"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/LCA.2018.2883431"},{"key":"e_1_3_2_41_2","first-page":"115","volume-title":"Proceedings of the 3rd USENIX Conference on File and Storage Technologies (FAST \u201904)","author":"Muniswamy-Reddy Kiran-Kumar","year":"2004","unstructured":"Kiran-Kumar Muniswamy-Reddy, Charles P. Wright, Andrew Himmer, and Erez Zadok. 2004. A versatile and user-oriented versioning file system. In Proceedings of the 3rd USENIX Conference on File and Storage Technologies (FAST \u201904). USENIX Association, USA, 115\u2013128."},{"key":"e_1_3_2_42_2","first-page":"1","volume-title":"Proceedings of the 56th Annual Design Automation Conference 2019","author":"Park Jisung","year":"2019","unstructured":"Jisung Park, Youngdon Jung, Jonghoon Won, Minji Kang, Sungjin Lee, and Jihong Kim. 2019. RansomBlocker: A low-overhead ransomware-proof SSD. In Proceedings of the 56th Annual Design Automation Conference 2019. ACM, New York, NY, 1\u20136."},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2016.46"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMSNETS.2018.8328219"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2011.2172207"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/SSCI.2017.8280842"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3229710.3229726"},{"key":"e_1_3_2_48_2","unstructured":"U.S. Securities and Exchange Commission. 2025. U.S. Securities and Exchange Commission (SEC). Retrieved from https:\/\/www.sec.govRegulatory agency overseeing U.S. securities markets"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICACCI.2017.8125850"},{"key":"e_1_3_2_50_2","doi-asserted-by":"crossref","first-page":"327","DOI":"10.1145\/3292006.3300041","volume-title":"Proceedings of the Ninth ACM Conference on Data and Application Security and Privacy","author":"Wang Peiying","year":"2019","unstructured":"Peiying Wang, Shijie Jia, Bo Chen, Luning Xia, and Peng Liu. 2019. MimosaFTL: Adding secure and practical ransomware defense strategy to flash translation layer. In Proceedings of the Ninth ACM Conference on Data and Application Security and Privacy. ACM, New York, NY, 327\u2013338."}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3797891","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,22]],"date-time":"2026-05-22T08:55:52Z","timestamp":1779440152000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3797891"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,22]]},"references-count":49,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3797891"],"URL":"https:\/\/doi.org\/10.1145\/3797891","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,22]]},"assertion":[{"value":"2025-06-06","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-01-02","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-05-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}