High-privilege insiders, such as IT administrators, pose a significant threat to data integrity, whether through accidental errors or malicious intent. Unauthorized modifications or deletions of critical data—such as system logs and access records—can cause severe operational and security disruptions. Traditionally, these threats are mitigated using hardware-based solutions such as Write-Once Read-Many (WORM) storage. While effective, these approaches have notable drawbacks, including high deployment costs and irreversible consumption of storage blocks, which cannot be reused once written. The goal of this article is to explore purely software-based solutions to these challenges. To this end, we design VaultFS, a software-only file system for Linux environments tailored for the protection of cold data—data that must remain accessible but unmodifiable. VaultFS enables writing through a standard file system interface while ensuring strict immutability and undeletability for a pre-defined time window, potentially infinite. Even threads operating with (effective)root-id permissions cannot alter or remove stored data, preserving integrity against privilege escalation threats. Achieving this requires addressing a number of key technical challenges, such as ensuring a trusted time reference to enforce temporal protection guarantees, and forcing a suited admission control policy to avoid any interaction with the file system that could be potentially dangerous, including access to the file system block device via common services offered by the Linux virtual file system. Furthermore, VaulFS mitigates storage-exhaustion Denial-of-Service (DoS) attacks, where untrusted applications flood the file system with non-removable content. We evaluate the integration of VaultFS with practical applications, demonstrating full compatibility with all seven backup tools assessed—including mysqldump and rsynch—and seamless integration with most of the video surveillance applications tested—including ivideon and ZoneMinder. Furthermore, our experimental evaluation shows that VaultFS incurs only a 7–12% performance overhead compared to the common Linux Ext4 file system under the usage of read/write intensive applications performing file-copy operations.

Caporaso, P., Bianchi, G., Quaglia, F. (2026). VaultFS: Data Integrity via Write-Once Software Support at the File System Level. DIGITAL THREATS, 7(2), 1-26 [10.1145/3797891].

VaultFS: Data Integrity via Write-Once Software Support at the File System Level

Caporaso, Pasquale
;
Bianchi, Giuseppe
;
Quaglia, Francesco
2026-01-01

Abstract

High-privilege insiders, such as IT administrators, pose a significant threat to data integrity, whether through accidental errors or malicious intent. Unauthorized modifications or deletions of critical data—such as system logs and access records—can cause severe operational and security disruptions. Traditionally, these threats are mitigated using hardware-based solutions such as Write-Once Read-Many (WORM) storage. While effective, these approaches have notable drawbacks, including high deployment costs and irreversible consumption of storage blocks, which cannot be reused once written. The goal of this article is to explore purely software-based solutions to these challenges. To this end, we design VaultFS, a software-only file system for Linux environments tailored for the protection of cold data—data that must remain accessible but unmodifiable. VaultFS enables writing through a standard file system interface while ensuring strict immutability and undeletability for a pre-defined time window, potentially infinite. Even threads operating with (effective)root-id permissions cannot alter or remove stored data, preserving integrity against privilege escalation threats. Achieving this requires addressing a number of key technical challenges, such as ensuring a trusted time reference to enforce temporal protection guarantees, and forcing a suited admission control policy to avoid any interaction with the file system that could be potentially dangerous, including access to the file system block device via common services offered by the Linux virtual file system. Furthermore, VaulFS mitigates storage-exhaustion Denial-of-Service (DoS) attacks, where untrusted applications flood the file system with non-removable content. We evaluate the integration of VaultFS with practical applications, demonstrating full compatibility with all seven backup tools assessed—including mysqldump and rsynch—and seamless integration with most of the video surveillance applications tested—including ivideon and ZoneMinder. Furthermore, our experimental evaluation shows that VaultFS incurs only a 7–12% performance overhead compared to the common Linux Ext4 file system under the usage of read/write intensive applications performing file-copy operations.
2026
Pubblicato
Rilevanza internazionale
Articolo
Esperti anonimi
Settore IINF-05/A - Sistemi di elaborazione delle informazioni
English
Con Impact Factor ISI
Security and privacy; File system security
https://dl.acm.org/doi/epdf/10.1145/3797891
Caporaso, P., Bianchi, G., Quaglia, F. (2026). VaultFS: Data Integrity via Write-Once Software Support at the File System Level. DIGITAL THREATS, 7(2), 1-26 [10.1145/3797891].
Caporaso, P; Bianchi, G; Quaglia, F
Articolo su rivista
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/2108/473431
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? 0
social impact