Solved

Confine data within a directory

Posted on 2011-02-22
4
398 Views
Last Modified: 2012-05-11
Hello,

Is there any way to confine data files within a directory? I think this is referred to as "confinement" or "type enforcement". I want to allow certain users the ability to access and change the data, but not be able to copy outside a particular folder. This would effectively mean any program that opens a file in the ‘confined’ folder would not be allowed to write to anywhere other than to a file in the same directory. Naturally we would need the ability to override this restriction – e.g. authorised users or password.

The issue is we have confidential information that staff need access to in order to view, change and process through batch programs, but we want to prevent the data being disclosed (accidently or deliberately) via web transfer, email, USB, CD, etc. I’m not able to block all access to the internet or prohibit email attachments, because these are services we need for other business requirements.

The environment is Windows Terminal Services. The type of files would include text, Excel & Access.

Does anyone have any suggestions?

Thanks!
0
Comment
Question by:markserv
  • 2
  • 2
4 Comments
 
LVL 10

Expert Comment

by:abbright
ID: 34958531
I don't know of a way to prevent users who have access to certain data to copy these to other locations. Actually I believe this is a feature that the application accessing the data needs to provide.
Anyway you may want to consider a solution like windows rights management services (http://en.wikipedia.org/wiki/Rights_Management_Services) which, encrypts sensitive data so that it can only be opened by authorized persons, even if distributed to other locations.
0
 

Author Comment

by:markserv
ID: 34967634
Thanks abbright for the reply, but I'm not sure this quite achieves what I'm after. It may do the job, however it sounds like applications need to be Rights Management Services compliant, which could be a show-stopper.
What I hoping for was some kind of system software that would put a 'wall' around the data (all files within a folder/sub-folders), so that even a user with permission to read & write to that directory cannot copy the data to a location outside the 'wall'.  As I said, I'm not sure this is even possible, but thought I ask the question!
0
 
LVL 10

Accepted Solution

by:
abbright earned 500 total points
ID: 34967670
I believe that theoretically this is possible though it may be impossible or at least very difficult doing so with Windows. As you want to achieve this with Excel and Access-files you need to have these applications on the machine and have them open the files. So the data is being read from the storage location to main memory at least. Now in order to prevent further distribution you need to make sure the data cannot be copied from memory elsewhere. The only thing I can think of is by restricting the network access of the relevant PC to not allow any connection (SMB, FTP, ...) to the outside and to seal all USB, floppy, CD-RW, ...-ports to not allow a copying of the files somewhere else. In the end if the users on the pc have some rights that allow the running of custom applications it is always possible to tunnel the data to some remote location given this location is somehow accessible, even via ping (http://www.neophob.com/2007/10/pingtunnel-for-windows-icmp-tunnel/).
0
 

Author Closing Comment

by:markserv
ID: 34975380
Hi abbrigh, I see your point. Unless one uses customised applications it’s probably impossible to place a 'wall' around it. Besides memory, many apps use temporary files as well. I'll look further into Windows Rights Management Services - that's probably the closest to what I'm after. Thanks for your help!
0

Featured Post

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Gmail Account risks 4 89
Access 2016 5 53
md5 password 3 62
Opinions of Sophos Intercept X and Endpoint Security 2 24
As technology users and professionals, we’re always learning. Our universal interest in advancing our knowledge of the trade is unmatched by most industries. It’s a curiosity that makes sense, given the climate of change. Within that, there lies a…
How do we balance the user experience (UX) with reasonable security measures? It can be done, if you keep these fundamentals in mind.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question