Design and implementation of virtual private services

被引:0
|
作者
Ioannidis, S [1 ]
Bellovin, SM [1 ]
Ioannidis, J [1 ]
Keromytis, AD [1 ]
Smith, JM [1 ]
机构
[1] Univ Penn, Philadelphia, PA 19104 USA
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Large scale distributed applications such as electronic commerce and online marketplaces combine network access with multiple storage and computational elements. The distributed responsibility for resource control creates new security and privacy issues, which are exacerbated by the complexity of the operating environment. In order to handle policies at multiple locations, the usual tools available (firewalls and compartmented file storage) get to be used in ways that are clumsy and prone to failure. We propose a new approach, virtual private services. Our approach relies on two functional divisions. First, we split policy specification and policy enforcement, providing local autonomy within the constraints of the global security policy Second, we create virtual security domains, each with its own security policy Every domain has an associated set of privileges and permissions restricting it to the resources it needs to use and the services it must perform. Virtual private services ensure security and privacy policies are adhered to through coordinated policy enforcement points. We describe our architecture and a prototype implementation, and present a preliminary performance evaluation confirming that our overhead of policy enforcement using is small.
引用
收藏
页码:269 / 274
页数:6
相关论文
共 50 条
  • [21] Design and implementation of virtual labs
    Ruiz Acero, Johanna Carolina
    Arias Morales, Karina Lisette
    Moreno Anselmi, Luis Angel
    ACADEMIA Y VIRTUALIDAD, 2011, 4 (01): : 49 - 60
  • [22] Moat: a virtual private network appliance and services platform
    Denker, JS
    Bellovin, SM
    Daniel, H
    Mintz, NL
    Killian, T
    Plotnick, MA
    USENIX ASSOCIATION PROCEEDINGS OF THE THIRTEENTH SYSTEMS ADMINISTRATION CONFERENCE (LISA XIII), 1999, : 251 - 260
  • [23] On packet loss estimation for virtual private networks services
    Zhang, DL
    Ionescu, D
    ICCCN 2004: 13TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, PROCEEDINGS, 2004, : 175 - 180
  • [24] Mobile virtual private dial-up services
    Chuah, MC
    Hernandez-Valencia, EJ
    BELL LABS TECHNICAL JOURNAL, 1999, 4 (03) : 51 - 72
  • [25] Optical Virtual Private Networks: Applications, Functionality and Implementation
    Stephen French
    Dimitrios Pendarakis
    Photonic Network Communications, 2004, 7 : 227 - 238
  • [26] Optical virtual private networks: Applications, functionality and implementation
    French, S
    Pendarakis, D
    PHOTONIC NETWORK COMMUNICATIONS, 2004, 7 (03) : 227 - 238
  • [27] Implementation of Virtual Private Network based on IPSec Protocol
    Wu, Jianwu
    2009 ETP INTERNATIONAL CONFERENCE ON FUTURE COMPUTER AND COMMUNICATION (FCC 2009), 2009, : 138 - 141
  • [28] Implementation of an FPGA based accelerator for Virtual Private Networks
    Cheung, OYH
    Leong, PHW
    2002 IEEE INTERNATIONAL CONFERENCE ON FIELD-PROGRAMMABLE TECHNOLOGY (FPT), PROCEEDINGS, 2002, : 34 - 41
  • [29] New approaches for virtual private network design
    Eisenbrand, Friedrich
    Grandoni, Fabrizio
    Oriolo, Gianpaolo
    Skutella, Martin
    SIAM JOURNAL ON COMPUTING, 2007, 37 (03) : 706 - 721
  • [30] The Genetic Approach for Design of Virtual Private Networks
    Kotenko, Igor
    Saenko, Igor
    2015 IEEE 18TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING (CSE), 2015, : 168 - 175