论文标题
Cybereye:通过视频从虚拟桌面获取数据
CyberEye: Obtaining Data from Virtual Desktop by Video
论文作者
论文摘要
VDI不再安全可靠。 VDI(虚拟桌面基础架构,也称为Cloud Desktop)被广泛用作工作接口,以避免数据渗透。使用VDI客户端,最终用户可以访问内部数据,而无需实际获得数据。在本文中,我们提出了一种名为Cybereye的新方法,以通过视频从VDI中提取数据传输。通过将数据文件编码为视频,在VDI中播放它,同时将其记录在主机PC中,我们可以通过视频格式获取数据的完整信息,然后对其进行解码以恢复原始数据文件。 Citrix Workspace和其他几个远程虚拟台式机上的概念证明已被强烈证明,被证明是Cybereye的可用性和可靠性。我们介绍了操作模型中的用法,以显示如何在技术工作部分中设计和实施。而且,我们已经向研究人员开放了源代码,以重现工作。
VDI is no longer safe and reliable anymore. VDI(Virtual Desktop Infrastructure, also called Cloud Desktop) is being widely used as working interface to avoid data exfiltration. With VDI client, end users can access internal data without obtaining data actually. In this paper, we present a new approach named CyberEye, to extract data from VDI by video even data transmission has been forbidden. By encoding data file to video, playing it in VDI meanwhile recording it in host PC, we can get full information of the data with video format, then decode it to recover the original data file. The proof-of-concept on Citrix Workspace and several other remote virtual desktops has strongly been proved the availability and reliability of the CyberEye. We introduce the usage in operation model to show how it's been designed and implemented in technical work section. And also, we have opened the source code to researchers for reproducing the work.