WinDlp
Abstract
Protecting confidential data from unauthorized disclosure is crucial. However, several challenges persist in developing effective data leakage prevention systems. First, these systems must detect and prevent data leakage across various formats and channels. Second, they must operate efficiently without disrupting normal workflows. Finally, they should adapt to diverse operational needs, scales, and objectives. This paper introduces WinDlp, a high-performance, programmable data leakage prevention system based on kernel-level monitoring for Windows platforms. By integrating multiple security measures with robust policy enforcement and access-control mechanisms, WinDlp effectively detects and prevents data leakage. Comprehensive evaluations demonstrate that WinDlp outperforms existing solutions in file encryption and decryption efficiency. Moreover, WinDlp maintains low central processing unit utilization, minimizing disruption to normal workflows. Finally, WinDlp provides flexible application programming interfaces that allow users to tailor the system to specific requirements.