An Attribute-Based Access Control Model for Secure Big Data Processing in Hadoop Ecosystem

被引:36
作者
Gupta, Maanak [1 ]
Patwa, Farhan [1 ]
Sandhu, Ravi [1 ]
机构
[1] Univ Texas San Antonio, ICS, C SPECC, Dept Comp Sci, San Antonio, TX 78249 USA
来源
PROCEEDINGS OF THE THIRD ACM WORKSHOP ON ATTRIBUTE-BASED ACCESS CONTROL (ABAC'18) | 2018年
关键词
Access Control; Hadoop Ecosystem; Big Data; Data Lake; Role Based; Attributes Based; Authorization; Trust;
D O I
10.1145/3180457.3180463
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Apache Hadoop is a predominant software framework for distributed compute and storage with capability to handle huge amounts of data, usually referred to as Big Data. This data collected from different enterprises and government agencies often includes private and sensitive information, which needs to be secured from unauthorized access. This paper proposes extensions to the current authorization capabilities offered by Hadoop core and other ecosystem projects, specifically Apache Ranger and Apache Sentry. We present a fine-grained attribute-based access control model, referred as HeABAC, catering to the security and privacy needs of multi-tenant Hadoop ecosystem. The paper reviews the current multi-layered access control model used primarily in Hadoop core (2.x), Apache Ranger (version 0.6) and Sentry (version 1.7.0), as well as a previously proposed RBAC extension (OT-RBAC). It then presents a formal attribute-based access control model for Hadoop ecosystem, including the novel concept of cross Hadoop services trust. It further highlights different trust scenarios, presents an implementation approach for HeABAC using Apache Ranger and, discusses the administration requirements of HeABAC operational model. Some comprehensive, real-world use cases are also discussed to reflect the application and enforcement of the proposed HeABAC model in Hadoop ecosystem.
引用
收藏
页码:13 / 24
页数:12
相关论文
共 48 条
  • [1] A model for attribute-based user-role assignment
    Al-Kahtani, MA
    Sandhu, R
    [J]. 18TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2002, : 353 - 362
  • [2] [Anonymous], 2017, XACML
  • [3] [Anonymous], 2016, Securing Hadoop: Security Recommendations for Hadoop Environments
  • [4] [Anonymous], 2016, Big Data: Securing Intel IT's Apache Hadoop Platform
  • [5] [Anonymous], 2009, TECH REP
  • [6] [Anonymous], 2017, SAML
  • [7] [Anonymous], 2012, STANFORD LAW REV ONL
  • [8] Bo Tang, 2013, 2013 IEEE 14th International Conference on Information Reuse & Integration (IRI), P129, DOI 10.1109/IRI.2013.6642463
  • [9] Privacy Aware Access Control for Big Data: A Research Roadmap
    Colombo, Pietro
    Ferrari, Elena
    [J]. BIG DATA RESEARCH, 2015, 2 (04) : 145 - 154
  • [10] Colombo Pietro, 2015, P SEBD 2015