Design and implementation of virtual private services

被引:0
|
作者
Ioannidis, S [1 ]
Bellovin, SM [1 ]
Ioannidis, J [1 ]
Keromytis, AD [1 ]
Smith, JM [1 ]
机构
[1] Univ Penn, Philadelphia, PA 19104 USA
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Large scale distributed applications such as electronic commerce and online marketplaces combine network access with multiple storage and computational elements. The distributed responsibility for resource control creates new security and privacy issues, which are exacerbated by the complexity of the operating environment. In order to handle policies at multiple locations, the usual tools available (firewalls and compartmented file storage) get to be used in ways that are clumsy and prone to failure. We propose a new approach, virtual private services. Our approach relies on two functional divisions. First, we split policy specification and policy enforcement, providing local autonomy within the constraints of the global security policy Second, we create virtual security domains, each with its own security policy Every domain has an associated set of privileges and permissions restricting it to the resources it needs to use and the services it must perform. Virtual private services ensure security and privacy policies are adhered to through coordinated policy enforcement points. We describe our architecture and a prototype implementation, and present a preliminary performance evaluation confirming that our overhead of policy enforcement using is small.
引用
收藏
页码:269 / 274
页数:6
相关论文
共 50 条
  • [1] Design and implementation of a kind of virtual private network
    Jiang, Tao
    Qin, Yang
    Zhou, Song
    Li, Xin-man
    Liu, Ji-ren
    Dongbei Daxue Xuebao/Journal of Northeastern University, 2000, 21 (02): : 136 - 139
  • [2] Network design scheme for Virtual Private Network services
    Takeda, Tomonori
    Matsuzaki, Ryuichi
    Inoue, Ichiro
    Urushidani, Shigeo
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2006, E89B (11) : 3046 - 3054
  • [3] Design and Implementation of Virtual Hadoop Cluster on Private Cloud
    Singh, Garima
    Singh, Anil Kumar
    DATA SCIENCE AND ANALYTICS, 2018, 799 : 61 - 71
  • [4] Design and Implementation Considerations for Virtual Reality in Human Services
    Benson, Cole L.
    McDonald, Chad
    Davis, Matthew J.
    Raines, Josh A.
    JOURNAL OF TECHNOLOGY IN HUMAN SERVICES, 2021, 39 (03) : 215 - 218
  • [5] Network Design for Layer 1 Virtual Private Network Services
    Takeda, Tomonori
    Matsuzaki, Ryuichi
    Inoue, Ichiro
    Urushidani, Shigeo
    2006 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-12, 2006, : 2731 - 2736
  • [6] Managed virtual private LAN services
    Hernandez-Valencia, EJ
    Koppol, P
    Lau, WC
    BELL LABS TECHNICAL JOURNAL, 2003, 7 (04) : 61 - 76
  • [7] Design and Implementation of an IPSec Virtual Private Network: A Case Study at the University of Namibia
    Hashiyana, Valerianus
    Haiduwa, Titus
    Suresh, Nalina
    Bratha, Aubrey
    Ouma, Flavia K.
    2020 IST-AFRICA CONFERENCE (IST-AFRICA), 2020,
  • [8] Virtual private network design
    Stougie, Leen
    SOR'07: PROCEEDINGS OF THE 9TH INTERNATIONAL SYMPOSIUM ON OPERATIONAL RESEARCH IN SLOVENIA, 2007, : 35 - 39
  • [9] Design and implementation of the secure compiler and virtual machine for developing secure IoT services
    Lee, YangSun
    Jeong, Junho
    Son, Yunsik
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2017, 76 : 350 - 357
  • [10] Design and testbed implementation of adaptive MPLS-DiffServ enabled Virtual Private Networks
    Jia, YX
    Guerrero, ML
    Kabranov, O
    Makrakis, D
    Barbosa, LO
    CCECE 2003: CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, VOLS 1-3, PROCEEDINGS: TOWARD A CARING AND HUMANE TECHNOLOGY, 2003, : 965 - 968