Design and implementation of virtual private services

被引:0
|
作者
Ioannidis, S [1 ]
Bellovin, SM [1 ]
Ioannidis, J [1 ]
Keromytis, AD [1 ]
Smith, JM [1 ]
机构
[1] Univ Penn, Philadelphia, PA 19104 USA
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Large scale distributed applications such as electronic commerce and online marketplaces combine network access with multiple storage and computational elements. The distributed responsibility for resource control creates new security and privacy issues, which are exacerbated by the complexity of the operating environment. In order to handle policies at multiple locations, the usual tools available (firewalls and compartmented file storage) get to be used in ways that are clumsy and prone to failure. We propose a new approach, virtual private services. Our approach relies on two functional divisions. First, we split policy specification and policy enforcement, providing local autonomy within the constraints of the global security policy Second, we create virtual security domains, each with its own security policy Every domain has an associated set of privileges and permissions restricting it to the resources it needs to use and the services it must perform. Virtual private services ensure security and privacy policies are adhered to through coordinated policy enforcement points. We describe our architecture and a prototype implementation, and present a preliminary performance evaluation confirming that our overhead of policy enforcement using is small.
引用
收藏
页码:269 / 274
页数:6
相关论文
共 50 条
  • [41] Cloud as Virtual Databases: Bridging Private Databases and Web Services
    Ohshima, Hiroaki
    Oyama, Satoshi
    Tanaka, Katsumni
    DATABASE SYSTEMS FOR ADVANCED APPLICATIONS, PT I, PROCEEDINGS, 2010, 5981 : 491 - +
  • [42] Analysis of IPSEC services and their integration in an IP virtual private network
    Achemlal, Mohammed
    Laurent, Maryline
    Annales des Telecommunications/Annals of Telecommunications, 2000, 55 (07): : 313 - 323
  • [43] Virtual private services: Coordinated policy enforcement for distributed applications
    Ioannidis, Sotiris
    Bellovin, Steven M.
    Ioannidis, John
    Keromytis, Angelos D.
    Anagnostakis, Kostas
    Smith, Jonathan M.
    International Journal of Network Security, 2007, 4 (01) : 69 - 80
  • [44] The design and implementation of a virtual conference system
    Shih, TK
    Huang, JY
    Hung, JC
    Wang, TH
    Pai, WC
    24TH ANNUAL INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COSPSAC 2000), 2000, 24 : 261 - 266
  • [45] Design and implementation of virtual multimedia classroom
    Zhu, Jiejie
    Hu, Weihua
    Pan, Zhigeng
    Jisuanji Fuzhu Sheji Yu Tuxingxue Xuebao/Journal of Computer-Aided Design and Computer Graphics, 2004, 16 (01): : 73 - 78
  • [46] Design and Implementation of Virtual Culture Museum
    Liu, Siyao
    Jia, Jinglin
    ICCSSE 2009: PROCEEDINGS OF 2009 4TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE & EDUCATION, 2009, : 686 - +
  • [47] On study of design and implementation of virtual fixtures
    Rodolfo Prada
    Shahram Payandeh
    Virtual Reality, 2009, 13 : 117 - 129
  • [48] On the Design and Implementation of a Virtual Machine for Arduino
    Zabala, Gonzalo
    Moran, Ricardo
    Teragni, Matias
    Blanco, Sebastian
    ROBOTICS IN EDUCATION: RESEARCH AND PRACTICES FOR ROBOTICS IN STEM EDUCATION, 2017, 457 : 207 - 218
  • [49] The design and implementation on IP virtual prototype
    Li, RF
    Zhou, Z
    Zhang, RQ
    Chen, YP
    Ren, XX
    SYSTEM SIMULATION AND SCIENTIFIC COMPUTING (SHANGHAI), VOLS I AND II, 2002, : 999 - 1004
  • [50] DESIGN AND IMPLEMENTATION OF A VIRTUAL CLASSROOM SYSTEM
    Omoregbe, Nicholas A.
    Azeta, Ambrose A.
    Bello-Osagie, Uyiosaifo
    Agarana, Michael C.
    ICERI2015: 8TH INTERNATIONAL CONFERENCE OF EDUCATION, RESEARCH AND INNOVATION, 2015, : 1176 - 1181