...
首页> 外文期刊>International Journal of Information Security >Enhancing grid security by fine-grained behavioral control and negotiation-based authorization
【24h】

Enhancing grid security by fine-grained behavioral control and negotiation-based authorization

机译:通过细粒度的行为控制和基于协商的授权来增强网格安全性

获取原文
获取原文并翻译 | 示例
           

摘要

Nowadays, Grid has become a leading technology in distributed computing. Grid poses a seamless sharing of heterogeneous computational resources belonging to different domains and conducts efficient collaborations between Grid users. The core Grid functionality defines computational services which allocate computational resources and execute applications submitted by Grid users. The vast models of collaborations and openness of Grid system require a secure, scalable, flexible and expressive authorization model to protect these computational services and Grid resources. Most of the existing authorization models for Grid have granularity to manage access to service invocations while behavioral monitoring of applications executed by these services remains a responsibility of a resource provider. The resource provider executes an application under a local account, and acknowledges all permissions granted to this account to the application. Such approach poses serious security threats to breach system functionality since applications submitted by users could be malicious. We propose a flexible and expressive policy-driven credential-based authorization system to protect Grid computational services against a malicious behavior of applications submitted for the execution. We split an authorization process into two levels: a coarse-grained level that manages access to a computational service; and a fine-grained level that monitors the behavior of applications executed by the computational service. Our framework guarantees that users authorized on a coarse-grained level behave as expected on the fine-grained level. Credentials obtained on the coarse-grained level reflect on fine-grained access decisions. The framework defines trust negotiations on coarse-grained level to overcome scalability problem, and preserves privacy of credentials and security policies of, both, Grid users and providers. Our authorization system was implemented to control access to the Globus Computational GRAM service. A comprehensive performance evaluation shows the practical scope of the proposed system.
机译:如今,Grid已成为分布式计算中的领先技术。网格带来了属于不同域的异构计算资源的无缝共享,并在网格用户之间进行了有效的协作。核心Grid功能定义了计算服务,这些服务分配计算资源并执行Grid用户提交的应用程序。网格系统的广泛协作和开放性模型需要安全,可扩展,灵活和可表达的授权模型来保护这些计算服务和网格资源。 Grid的大多数现有授权模型都具有粒度来管理对服务调用的访问,而对由这些服务执行的应用程序的行为监视仍然是资源提供者的责任。资源提供者在本地帐户下执行应用程序,并向该应用程序确认授予该帐户的所有权限。由于用户提交的应用程序可能是恶意的,因此这种方法对违反系统功能构成了严重的安全威胁。我们提出了一种灵活且具有表现力的,基于策略的基于凭证的授权系统,以保护Grid计算服务免受提交用于执行的应用程序的恶意行为。我们将授权过程分为两个级别:粗粒度级别,用于管理对计算服务的访问;一个细粒度的级别,用于监视计算服务执行的应用程序的行为。我们的框架可确保在粗粒度级别上授权的用户在细粒度级别上的行为符合预期。在粗粒度级别获得的凭据反映了细粒度的访问决策。该框架在粗粒度级别定义了信任协商,以克服可伸缩性问题,并保留Grid用户和提供者的凭据和安全策略的私密性。我们实施了授权系统,以控制对Globus计算GRAM服务的访问。全面的性能评估显示了该系统的实用范围。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号