首页> 外文会议>Reliable Distributed Systems, 2005. SRDS 2005. 24th IEEE Symposium on >Enforcing enterprise-wide policies over standard client-server interactions
【24h】

Enforcing enterprise-wide policies over standard client-server interactions

机译:在标准客户端-服务器交互上执行企业范围的策略

获取原文

摘要

We propose and evaluate a novel framework for enforcing global coordination and control policies over interacting software components in enterprise computing environments. This framework combines a per-node reference monitor with two existing coordination and control systems to enforce policies that, among other properties, are stateful and communal. Each reference monitor filters messages exchanged between the interacting software components similar to a firewall, passing only messages that are allowed by the policies in effect. This filtering approach decouples coordination and control from application implementation, allowing the coordination and control mechanism and application implementations to evolve independently of each other. We demonstrate the power of our framework by using it to specify and enforce an RBAC policy with delegation, revocation, and separation-of-duty over accesses to a cluster of NFS and SMB file servers without changing any client or server implementations. Measurements show that our framework imposes acceptable overheads when enforcing this policy.
机译:我们提出并评估了一种新颖的框架,该框架可对企业计算环境中的交互软件组件实施全局协调和控制策略。该框架将每个节点的参考监视器与两个现有的协调和控制系统结合在一起,以执行具有状态和公共属性的策略。每个参考监视器都会过滤与防火墙类似的交互软件组件之间交换的消息,仅传递有效策略允许的消息。这种过滤方法使协调和控制与应用程序实现脱钩,从而允许协调和控制机制与应用程序实现彼此独立发展。我们通过使用框架来指定和实施RBAC策略,并通过对NFS和SMB文件服务器群集的访问进行委派,吊销和职责分离来展示我们框架的强大功能,而无需更改任何客户端或服务器实现。度量表明,在执行此策略时,我们的框架施加了可接受的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号