首页> 外文OA文献 >Security Policy Definition and Enforcement in Distributed Systems
【2h】

Security Policy Definition and Enforcement in Distributed Systems

机译:分布式系统中的安全策略定义和执行

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Security in computer systems is concerned with protecting resources from unauthorized access while ensuring legitimate requests can be satisfied all the time. The recent growth of computer systems both in scale and complexity poses tremendous management challenges. Policy-based systems management is a very promising solution in this scenario. It allows the separation of the rules that govern the behavior choices of a system from the provided functionality, and can be adapted to handle a large number of system elements. In the past two decades there have been many advances in the field of policy research. Although existing solutions in centralized systems are well-established, they do not work nearly as well in distributed environments because of scalability, network partitions, and the heterogeneity of the endpoints. This dissertation contributes to this endeavor by proposing three novel techniques to address the problem of security policy definition and enforcement in large-scale distributed systems. To correctly enforce service and security requirements from users who have no intimate knowledge of the underlying systems, we introduce the first distributed policy refinement solution that translates high-level policies into low-level implementable rules, for which the syntax and semantics can be fully interpreted by individual enforcement points. Taking advantage of both the centralized and end-to-end enforcement approaches, we propose a novel policy algebra framework for policy delegation, composition and analysis. As a concrete instantiation of policy delegation enabled by the algebraic framework, we invent a novel firewall system, called ROFL (routing as the firewall layer), that implements packet filtering using the underlying routing techniques. ROFL implements a form of ubiquitous enforcement, and is able to drop malicious packets closer to their origins to save transmission bandwidth and battery power, especially for resource-limited devices in mobile ad hoc networks (MANET). The correctness and consistency of ROFL can be verified using policy algebra. It provides formalisms to address the complexity of distributed environments, increase assurance and show how to tune tradeoffs and improve security with ubiquitous enforcement. To demonstrate the effectiveness and efficiency of ROFL as a high-performance firewall mechanism, we analyze its performance quantitatively and conduct experiments in a simulated environment with two ad-hoc routing protocols. Empirical study shows that the increase in traffic for handling ROFL routing messages is more than outweighed by the savings by early drops of unwanted traffic.
机译:计算机系统的安全性涉及保护资源免受未经授权的访问,同时确保始终满足合法请求。计算机系统的规模和复杂性的最新增长带来了巨大的管理挑战。在这种情况下,基于策略的系统管理是非常有前途的解决方案。它允许从提供的功能中分离出管理系统行为选择的规则,并且可以适应处理大量的系统元素。在过去的二十年中,政策研究领域取得了许多进步。尽管集中式系统中的现有解决方案已经很好地建立起来,但是由于可伸缩性,网络分区和端点的异构性,它们在分布式环境中的效果不佳。本文通过提出三种新颖的技术来解决大规模分布式系统中安全策略定义和执行问题,为这一工作做出了贡献。为了正确执行对底层系统不了解的用户的服务和安全要求,我们引入了第一个分布式策略优化解决方案,该解决方案将高级策略转换为可实现的低级规则,可以完全解释其语法和语义。由个人执行点。利用集中执行和端到端执行方法,我们提出了一个新的政策代数框架,用于政策授权,组成和分析。作为代数框架支持的策略委派的具体实例,我们发明了一种新颖的防火墙系统,称为ROFL(路由作为防火墙层),该系统使用底层路由技术来实现数据包筛选。 ROFL实现了一种普遍执行的形式,能够将恶意数据包丢弃到更接近其来源的位置,以节省传输带宽和电池电量,特别是对于移动自组织网络(MANET)中资源受限的设备而言。 ROFL的正确性和一致性可以使用策略代数进行验证。它提供形式主义以解决分布式环境的复杂性,增加保证并展示如何通过无处不在的执行来权衡取舍和提高安全性。为了证明ROFL作为高性能防火墙机制的有效性和效率,我们定量分析了其性能,并在带有两个临时路由协议的模拟环境中进行了实验。经验研究表明,处理ROFL路由消息所增加的流量远远超过了因减少不必要的流量而节省的成本。

著录项

  • 作者

    Zhao Hang;

  • 作者单位
  • 年度 2012
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号