Neon: System Support for Derived Data Management
Modern organizations face increasingly complex information management requirements. A combination of commercial needs, legal liability and regulatory imperatives has created a patchwork of mandated policies. Among these, personally identifying customer records must be carefully access-controlled, sensitive files must be encrypted on mobile computers to guard against physical theft, and intellectual property must be protected from both exposure and "Poisoning." However, enforcing such policies can be quite difficult in practice since users routinely share data over networks and derive new files from these inputs - incidentally laundering any policy restrictions. In this paper, the authors describe a virtual machine monitor system called Neon that transparently labels derived data using byte-level "Tints" and tracks these labels end to end across commodity applications, operating systems and networks.