Decentralized Enforcement of Security Policies for Distributed Computational Systems

被引:0
作者
Orlovsky, Arie [1 ]
Raz, Danny [1 ]
机构
[1] Technion Israel Inst Technol, IL-3200 Technion, Haifa, Israel
来源
APPLIED COMPUTING 2007, VOL 1 AND 2 | 2007年
关键词
Security; Distributed System; Policy Enforement;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The shift from single server environments to globally distributed systems presents a great challenge in terms of defining and enforcing appropriate security policies. This is, among other things, due to the fact that the actual order between events in an asynchronous distributed environments is not always defined. In addition, security policies often depend on the actual information exchange among the distributed entities. In this paper we study the problem of adapting security policies to distributed environments such as grids and mobile code systems. We define global security policy and indicate some of the difficulties in translating local policies to the distributed environment. Then, we propose an efficient and scalable decentralized security mechanism for the enforcement of global stateful security policies in distributed computational systems. The mechanism is based on multiple instances of execution monitors (smart sandboxes) running on the distributed entities and on efficient security information sharing among them. We show that the subclasses of EM policies enforceable by this mechanism contain useful and real live security policies such as global information flow policies.
引用
收藏
页码:241 / 248
页数:8
相关论文
共 50 条
  • [41] Formal enforcement and management of obligation policies
    Elrakaiby, Yehia
    Cuppens, Frederic
    Cuppens-Boulahia, Nora
    DATA & KNOWLEDGE ENGINEERING, 2012, 71 (01) : 127 - 147
  • [42] ENHANCING WORKFLOW SECURITY FOR LARGE SCALE DISTRIBUTED SYSTEMS
    Pop, Florin
    Drenea, Alexandru Corneliu
    Cristea, Valentin
    ECEC' 2011:17TH EUROPEAN CONCURRENT ENGINEERING CONFERENCE / 7TH FUTURE BUSINESS TECHNOLOGY CONFERENCE, 2011, : 49 - 53
  • [43] Corrective Enforcement: A New Paradigm of Security Policy Enforcement by Monitors
    Khoury, Raphael
    Tawbi, Nadia
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2012, 15 (02)
  • [44] Basic concept and decentralized autonomous control of super-distributed energy systems
    Yasuda, K
    Ishii, T
    ELECTRICAL ENGINEERING IN JAPAN, 2005, 151 (01) : 43 - 55
  • [45] Exhaustive distributed intrusion detection system for UAVs attacks detection and security enforcement (E-DIDS)
    Tlili, Fadhila
    Ayed, Samiha
    Fourati, Lamia Chaari
    COMPUTERS & SECURITY, 2024, 142
  • [46] SDN-Based Security Enforcement Framework for Data Sharing Systems of Smart Healthcare
    Meng, Yunfei
    Huang, Zhiqiu
    Shen, Guohua
    Ke, Changbo
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (01): : 308 - 318
  • [47] Security architecture for law enforcement agencies
    Uruena, Manuel
    Machnik, Petr
    Niemiec, Marcin
    Stoianov, Nikolai
    MULTIMEDIA TOOLS AND APPLICATIONS, 2016, 75 (17) : 10709 - 10732
  • [48] Type enforcement: The new security model
    Thomsen, D
    MULTIMEDIA: FULL-SERVICE IMPACT ON BUSINESS, EDUCATION, AND THE HOME, 1996, 2617 : 143 - 150
  • [49] Multi-Level security model in distributed database systems
    Bakir, Cigdem
    Guclu, Mehmet
    PAMUKKALE UNIVERSITY JOURNAL OF ENGINEERING SCIENCES-PAMUKKALE UNIVERSITESI MUHENDISLIK BILIMLERI DERGISI, 2022, 28 (02): : 266 - 276
  • [50] A FORMAL PROTECTION MODEL OF SECURITY IN CENTRALIZED, PARALLEL, AND DISTRIBUTED SYSTEMS
    BENSON, GS
    AKYILDIZ, IF
    APPELBE, WF
    ACM TRANSACTIONS ON COMPUTER SYSTEMS, 1990, 8 (03): : 183 - 213