首页> 外文会议>31st International Conference on Distributed Computing Systems >sfatables: A Firewall-like Policy Engine for Federated Systems
【24h】

sfatables: A Firewall-like Policy Engine for Federated Systems

机译:可扩展性:用于联合系统的类似防火墙的策略引擎

获取原文
获取外文期刊封面目录资料

摘要

Recent efforts to federate computation and communication resources across organizational boundaries face a challenge in establishing the policies by which one organization's users can access resources in other organizations. This paper describes an approach to defining, communicating, analyzing, and enforcing resource allocation policies in this new setting. Our approach was designed to address the needs of Planet Lab, but we demonstrate through a range of examples that it is general enough to accommodate a diverse collection of computing facilities. Our policy engine is implemented in a specific tool chain, called {tt sfatables}, that is patterned after the {tt iptables} mechanism used to define packet processing policies for network traffic. The interface to our policy engine thus uses the familiar paradigm of a {tt firewall} and provides a flexible interface for resource owners to specify access policies for their resources. Our implementation makes it possible to precisely document policies, query, and analyze them.
机译:跨组织边界联合计算和通信资源的最新努力在建立策略时面临一个挑战,一个组织的用户可以通过该策略访问其他组织中的资源。本文介绍了一种在此新设置中定义,通信,分析和强制执行资源分配策略的方法。我们的方法旨在满足Planet Lab的需求,但我们通过一系列示例证明了该方法足以容纳各种计算设施。我们的策略引擎是在称为{tt sfatables}的特定工具链中实现的,该工具链是在用于定义网络流量的数据包处理策略的{tt iptables}机制之后仿制的。因此,我们的策略引擎的接口使用了{tt Firewall}熟悉的范例,并为资源所有者提供了灵活的接口来为其资源指定访问策略。我们的实施使精确记录策略,查询和分析策略成为可能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号