Decentralized Enforcement of Security Policies for Distributed Computational Systems

被引:0
|
作者
Orlovsky, Arie [1 ]
Raz, Danny [1 ]
机构
[1] Technion Israel Inst Technol, IL-3200 Technion, Haifa, Israel
来源
APPLIED COMPUTING 2007, VOL 1 AND 2 | 2007年
关键词
Security; Distributed System; Policy Enforement;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The shift from single server environments to globally distributed systems presents a great challenge in terms of defining and enforcing appropriate security policies. This is, among other things, due to the fact that the actual order between events in an asynchronous distributed environments is not always defined. In addition, security policies often depend on the actual information exchange among the distributed entities. In this paper we study the problem of adapting security policies to distributed environments such as grids and mobile code systems. We define global security policy and indicate some of the difficulties in translating local policies to the distributed environment. Then, we propose an efficient and scalable decentralized security mechanism for the enforcement of global stateful security policies in distributed computational systems. The mechanism is based on multiple instances of execution monitors (smart sandboxes) running on the distributed entities and on efficient security information sharing among them. We show that the subclasses of EM policies enforceable by this mechanism contain useful and real live security policies such as global information flow policies.
引用
收藏
页码:241 / 248
页数:8
相关论文
共 50 条
  • [21] Requirement Analysis of IoT Security in Distributed Systems
    Mbanaso, U. M.
    Chukwudebe, G. A.
    2017 IEEE 3RD INTERNATIONAL CONFERENCE ON ELECTRO-TECHNOLOGY FOR NATIONAL DEVELOPMENT (NIGERCON), 2017, : 777 - 781
  • [22] SECURITY RECOMMENDATIONS FOR IMPLEMENTATION IN DISTRIBUTED HEALTHCARE SYSTEMS
    Lhotska, Lenka
    Aubrecht, Petr
    Valls, Aida
    Gibert, Karina
    42ND ANNUAL 2008 IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY, PROCEEDINGS, 2008, : 76 - +
  • [23] Distributed Security in Multi-agent Systems
    Mois, George Dan
    Flonta, Stelian
    Stefan, Iulia
    Enyedi, Szilard
    Miclea, Liviu Cristian
    CONTROL ENGINEERING AND APPLIED INFORMATICS, 2010, 12 (03): : 47 - 51
  • [24] Security and safety architectural framework of distributed systems
    Li Zhongwen
    Advances in Computational Methods in Sciences and Engineering 2005, Vols 4 A & 4 B, 2005, 4A-4B : 1745 - 1748
  • [25] Security policies definition and enforcement utilizing policy control function framework in 5G
    Gomez, German Peinado
    Batalla, Jordi Mongay
    Miche, Yoan
    Holtmanns, Silke
    Mavromoustakis, Constandinos X.
    Mastorakis, George
    Haider, Noman
    COMPUTER COMMUNICATIONS, 2021, 172 : 226 - 237
  • [26] Coordinating randomized policies for increasing security of agent systems
    Paruchuri, Praveen
    Pearce, Jonathan P.
    Marecki, Janusz
    Tambe, Milind
    Ordonez, Fernando
    Kraus, Sarit
    INFORMATION TECHNOLOGY & MANAGEMENT, 2009, 10 (01) : 67 - 79
  • [27] An agent approach for providing security in distributed systems
    Skakun, Serhiy
    Kussul, Nataliya
    TCSET 2006: MODERN PROBLEMS OF RADIO ENGINEERING, TELECOMMUNICATIONS AND COMPUTER SCIENCE, PROCEEDINGS, 2006, : 212 - 215
  • [28] A Novel Security Schema for Distributed File Systems
    Zarei, Bager
    Asadi, Mehdi
    Nourizadeh, Saced
    Begdillo, Shapour Jodi
    ADVANCES IN COMPUTER AND INFORMATIOM SCIENCES AND ENGINEERING, 2008, : 305 - +
  • [29] Coordinating randomized policies for increasing security of agent systems
    Praveen Paruchuri
    Jonathan P. Pearce
    Janusz Marecki
    Milind Tambe
    Fernando Ordóñez
    Sarit Kraus
    Information Technology and Management, 2009, 10 : 67 - 79
  • [30] Tractable enforcement of declassification policies
    Barthe, Gilles
    Cavadini, Salvador
    Rezk, Tamara
    CSF 2008: 21ST IEEE COMPUTER SECURITY FOUNDATIONS SYMPOSIUM, PROCEEDINGS, 2008, : 83 - 97