SECapacity: A Secure Capacity Scheduler in YARN

被引:2
作者
Dong, Chuntao [1 ,2 ]
Shen, Qingni [1 ,2 ]
Cheng, Lijing [1 ,2 ]
Yang, Yahui [1 ,2 ]
Wu, Zhonghai [1 ,2 ]
机构
[1] Peking Univ, Sch Software & Microelect, Beijing, Peoples R China
[2] Peking Univ, MoE Key Lab Network & Software Assurance, Beijing, Peoples R China
来源
INFORMATION AND COMMUNICATIONS SECURITY, ICICS 2016 | 2016年 / 9977卷
关键词
Big data platform; Hadoop; User-classification based scheduling; SECapacity scheduler;
D O I
10.1007/978-3-319-50011-9_15
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, aiming to the requirement that isolation of user's job and data security, we deeply analyze the mainstream computing framework Hadoop YARN, and start with the core module of YARN - resource scheduler. Using the existing label-based scheduling policy, we design and implement a SECapacity scheduler. Our main work including: First, according to the principle of least privilege, we propose a user-classification based scheduling policy, which divided users to several levels based on their attributes, then restrict which nodes could be used by this user according to the user level. Second, we design and implement a SECapacity scheduler to implement user-classification based scheduling. Third, we verify and analyze the effectiveness and efficiency of SECapacity scheduler, the results shows that SECapacity scheduler can ensure 100% isolation of users at different levels, and the performance overhead is about 6.95%.
引用
收藏
页码:184 / 194
页数:11
相关论文
共 8 条
[1]  
[Anonymous], ACM COMPUT SURVEYS
[2]  
[Anonymous], 2010, NSDI
[3]  
[Anonymous], M2R ENABLING STRONGE
[4]  
Dean J, 2004, USENIX ASSOCIATION PROCEEDINGS OF THE SIXTH SYMPOSIUM ON OPERATING SYSTEMS DESIGN AND IMPLEMENTATION (OSDE '04), P137
[5]  
Dong C., 2016, LNCS, V9543, P458, DOI [10.1007/978-3-319-29814-6_39, DOI 10.1007/978-3-319-29814-6]
[6]   Observing and Preventing Leakage in MapReduce [J].
Ohrimenko, Olga ;
Costa, Manuel ;
Fournet, Cedric ;
Gkantsidis, Christos ;
Kohlweiss, Markulf ;
Sharma, Divya .
CCS'15: PROCEEDINGS OF THE 22ND ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2015, :1570-1581
[7]  
Vavilapalli V.K., P 4 ANN S CLOUD COMP, DOI [10.1145/2523616.2523633, DOI 10.1145/2523616.2523633]
[8]   SecureMR: A Service Integrity Assurance Framework for Map Reduce [J].
Wei, Wei ;
Du, Juan ;
Yu, Ting ;
Gu, Xiaohui .
25TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, 2009, :73-82