...
首页> 外文期刊>Performance evaluation review >XEngine: A Fast and Scalable XACML Policy Evaluation Engine
【24h】

XEngine: A Fast and Scalable XACML Policy Evaluation Engine

机译:XEngine:快速且可扩展的XACML策略评估引擎

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

XACML has become the de facto standard for specifying access control policies for various applications, especially web services. With the explosive growth of web applications deployed on the Internet, XACML policies grow rapidly in size and complexity, which leads to longer request processing time. This paper concerns the performance of request processing, which is a critical issue and so far has been overlooked by the research community. In this paper, we propose XEngine, a scheme for efficient XACML policy evaluation. XEngine first converts a textual XACML policy to a numerical policy. Second, it converts a numerical policy with complex structures to a numerical policy with a normalized structure. Third, it converts the normalized numerical policy to tree data structures for efficient processing of requests. To evaluate the performance of XEngine, we conducted extensive experiments on both real-life and synthetic XACML policies. The experimental results show that XEngine is orders of magnitude more efficient than Sun PDP, and the performance difference between XEngine and Sun PDP grows almost linearly with the number of rules in XACML policies. For XACML policies of small sizes (with hundreds of rules), XEngine is one to two orders of magnitude faster than the widely deployed Sun PDP. For XACML policies of large sizes (with thousands of rules), XEngine is three to four orders of magnitude faster than Sun PDP.
机译:XACML已成为为各种应用程序(尤其是Web服务)指定访问控制策略的事实上的标准。随着部署在Internet上的Web应用程序的爆炸性增长,XACML策略的大小和复杂性迅速增长,这导致更长的请求处理时间。本文涉及请求处理的性能,这是一个至关重要的问题,到目前为止,它已被研究团体所忽略。在本文中,我们提出了XEngine,这是一种有效的XACML策略评估方案。 XEngine首先将文本XACML策略转换为数字策略。其次,它将具有复杂结构的数字策略转换为具有规范化结构的数字策略。第三,它将规范化的数字策略转换为树数据结构,以高效处理请求。为了评估XEngine的性能,我们对实际和综合XACML策略进行了广泛的实验。实验结果表明,XEngine的效率比Sun PDP高几个数量级,并且XEngine和Sun PDP之间的性能差异几乎随XACML策略中规则的数量线性增长。对于较小的XACML策略(具有数百个规则),XEngine比广泛部署的Sun PDP快一到两个数量级。对于大型XACML策略(具有数千个规则),XEngine比Sun PDP快三到四个数量级。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号