首页> 外文期刊>Future generation computer systems >Improving Mandatory Access Control for HPC clusters
【24h】

Improving Mandatory Access Control for HPC clusters

机译:改善HPC群集的强制访问控制

获取原文
获取原文并翻译 | 示例
       

摘要

HPC clusters are costly resources, hence nowadays these structures tend to be co-financed by several partners. A cluster administrator has to be designated, whose duties include, amongst others, the prevention of accidental data leakage or theft. Linux has been chosen as an operating system for the CEA's computing platforms. However, strong system security solutions such as SELinux are usually difficult to set up in large environments.This article presents how we have adapted a mac mechanism in order to enforce confidentiality and integrity between a large number of users. First we define our security objectives, and show how they direct our technical choices. Then we present how confinement was achieved using the SELinux security mechanism, and how various attack scenarios were addressed. We then focus on the use of Mandatory Categories, access control on high bandwidth network filesystems and the integration of new users and applications. We discuss some residual technical challenges. Finally, we present benchmark results and validate the acceptable performance impact of our deployment on a modern cluster.
机译:HPC集群是昂贵的资源,因此如今,这些结构倾向于由多个合作伙伴共同出资。必须指定集群管理员,其职责包括防止意外数据泄漏或盗窃。 Linux已被选作CEA计算平台的操作系统。但是,通常很难在大型环境中设置强大的系统安全解决方案(例如SELinux)。本文介绍了我们如何采用mac机制来在大量用户之间实施机密性和完整性。首先,我们定义安全目标,并说明它们如何指导我们的技术选择。然后,我们介绍如何使用SELinux安全机制实现限制,以及如何解决各种攻击情况。然后,我们重点介绍强制性类别的使用,高带宽网络文件系统上的访问控制以及新用户和应用程序的集成。我们讨论了一些剩余的技术挑战。最后,我们提供基准测试结果并验证我们在现代集群上部署对性能的可接受影响。

著录项

  • 来源
    《Future generation computer systems》 |2013年第3期|876-885|共10页
  • 作者

    M. Blanc; J.-F. Lalande;

  • 作者单位

    CEA/DAM/DIF, Bruyeres-le-Chatel, 91297 Arpajon, France;

    Centre-Val de Loire Universite, LIFO, ENSl de Bourges, 88 bd Lahitolle, 18020 Bourges, France;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    HPC clusters; access control; benchmarking;

    机译:HPC集群;访问控制;基准测试;
  • 入库时间 2022-08-18 02:16:57

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号