首页> 外文会议>Data Engineering, ICDE, 2009 IEEE 25th International Conference on >Unified Declarative Platform for Secure Netwoked Information Systems
【24h】

Unified Declarative Platform for Secure Netwoked Information Systems

机译:安全网络信息系统的统一声明平台

获取原文

摘要

We present a unified declarative platform for specifying, implementing, and analyzing secure networked information systems. Our work builds upon techniques from logic-based trust management systems, declarative networking, and data analysis via provenance. We make the following contributions. First, we propose the Secure Network Datalog (SeNDlog) language that unifies Binder, a logic-based language for access control in distributed systems, and Network Datalog, a distributed recursive query language for declarative networks. SeNDlog enables network routing, information systems, and their security policies to be specified and implemented within a common declarative framework. Second, we extend existing distributed recursive query processing techniques to execute SeNDlog programs that incorporate authenticated communication among untrusted nodes. Third, we demonstrate that distributed network provenance can be supported naturally within our declarative framework for network security analysis and diagnostics. Finally, using a local cluster and the PlanetLab testbed, we perform a detailed performance study of a variety of secure networked systems implemented using our platform.
机译:我们提供了一个统一的声明性平台,用于指定,实施和分析安全的网络信息系统。我们的工作建立在基于逻辑的信任管理系统,声明性网络以及通过来源进行数据分析的技术之上。我们做出以下贡献。首先,我们提出一种安全网络数据日志(SeNDlog)语言,该语言将Binder(一种用于分布式系统中访问控制的基于逻辑的语言)与网络数据日志(一种用于声明性网络的分布式递归查询语言)统一起来。 SeNDlog使网络路由,信息系统及其安全策略可以在一个通用的声明框架内指定和实现。其次,我们扩展现有的分布式递归查询处理技术,以执行SeNDlog程序,该程序结合了不受信任节点之间的经过身份验证的通信。第三,我们证明了在我们用于网络安全分析和诊断的声明性框架内自然可以支持分布式网络源。最后,我们使用本地集群和PlanetLab测试平台,对使用我们的平台实施的各种安全联网系统进行了详细的性能研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号