Design and implementation of virtual private services

被引:0
|
作者
Ioannidis, S [1 ]
Bellovin, SM [1 ]
Ioannidis, J [1 ]
Keromytis, AD [1 ]
Smith, JM [1 ]
机构
[1] Univ Penn, Philadelphia, PA 19104 USA
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Large scale distributed applications such as electronic commerce and online marketplaces combine network access with multiple storage and computational elements. The distributed responsibility for resource control creates new security and privacy issues, which are exacerbated by the complexity of the operating environment. In order to handle policies at multiple locations, the usual tools available (firewalls and compartmented file storage) get to be used in ways that are clumsy and prone to failure. We propose a new approach, virtual private services. Our approach relies on two functional divisions. First, we split policy specification and policy enforcement, providing local autonomy within the constraints of the global security policy Second, we create virtual security domains, each with its own security policy Every domain has an associated set of privileges and permissions restricting it to the resources it needs to use and the services it must perform. Virtual private services ensure security and privacy policies are adhered to through coordinated policy enforcement points. We describe our architecture and a prototype implementation, and present a preliminary performance evaluation confirming that our overhead of policy enforcement using is small.
引用
收藏
页码:269 / 274
页数:6
相关论文
共 50 条
  • [31] Minimal cost design of Virtual Private Networks
    Liang, H
    Kabranov, O
    Makrakis, D
    Orozco-Barbosa, L
    IEEE CCEC 2002: CANADIAN CONFERENCE ON ELECTRCIAL AND COMPUTER ENGINEERING, VOLS 1-3, CONFERENCE PROCEEDINGS, 2002, : 1610 - 1615
  • [32] ATM VIRTUAL PRIVATE NETWORK DESIGN ALTERNATIVES
    CROCETTI, P
    FOTEDAR, S
    FRATTA, L
    GALLASSI, G
    GERLA, M
    COMPUTER COMMUNICATIONS, 1995, 18 (01) : 24 - 31
  • [33] New approaches for virtual private network design
    Eisenbrand, F
    Grandoni, F
    Oriolo, G
    Skutella, M
    AUTOMATA, LANGUAGES AND PROGRAMMING, PROCEEDINGS, 2005, 3580 : 1151 - 1162
  • [34] On virtual private networks security design issues
    Cheung, KH
    Misic, J
    COMPUTER NETWORKS, 2002, 38 (02) : 165 - 179
  • [35] Evolutionary Algorithms for Design of Virtual Private Networks
    Kotenko, Igor
    Saenko, Igor
    INTELLIGENT DISTRIBUTED COMPUTING XII, 2018, 798 : 287 - 297
  • [36] Analysis of IPSEC services and their integration in an IP virtual private network
    Achemlal, M
    Laurent, M
    ANNALES DES TELECOMMUNICATIONS-ANNALS OF TELECOMMUNICATIONS, 2000, 55 (7-8): : 313 - 323
  • [37] Private Practice, Private Insurance, and Private Pay Mental Health Services: An Understudied Area in Implementation Science
    Hannah E. Frank
    Gracelyn Cruden
    Margaret E. Crane
    Administration and Policy in Mental Health and Mental Health Services Research, 2024, 51 : 1 - 6
  • [38] Private Practice, Private Insurance, and Private Pay Mental Health Services: An Understudied Area in Implementation Science
    Frank, H. E.
    Cruden, G.
    Crane, M. E.
    ADMINISTRATION AND POLICY IN MENTAL HEALTH AND MENTAL HEALTH SERVICES RESEARCH, 2024, 51 (01) : 1 - 6
  • [39] Secure Virtual Private LAN Services: An Overview with Performance Evaluation
    Liyanage, Madhusanka
    Okwuibe, Jude
    Ylianttila, Mika
    Gurtov, Andrei
    2015 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATION WORKSHOP (ICCW), 2015, : 2231 - 2237
  • [40] Enhancing Security, Scalability and Flexibility of Virtual Private LAN Services
    Liyanage, Madhusanka
    Ylianttila, Mika
    Gurtov, Andrei
    2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY (CIT), 2017, : 286 - 291