Decentralized Enforcement of Security Policies for Distributed Computational Systems

被引:0
|
作者
Orlovsky, Arie [1 ]
Raz, Danny [1 ]
机构
[1] Technion Israel Inst Technol, IL-3200 Technion, Haifa, Israel
关键词
Security; Distributed System; Policy Enforement;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The shift from single server environments to globally distributed systems presents a great challenge in terms of defining and enforcing appropriate security policies. This is, among other things, due to the fact that the actual order between events in an asynchronous distributed environments is not always defined. In addition, security policies often depend on the actual information exchange among the distributed entities. In this paper we study the problem of adapting security policies to distributed environments such as grids and mobile code systems. We define global security policy and indicate some of the difficulties in translating local policies to the distributed environment. Then, we propose an efficient and scalable decentralized security mechanism for the enforcement of global stateful security policies in distributed computational systems. The mechanism is based on multiple instances of execution monitors (smart sandboxes) running on the distributed entities and on efficient security information sharing among them. We show that the subclasses of EM policies enforceable by this mechanism contain useful and real live security policies such as global information flow policies.
引用
收藏
页码:241 / 248
页数:8
相关论文
共 50 条
  • [31] Achieving dynamicity in security policies enforcement using aspects
    Samiha Ayed
    Muhammad Sabir Idrees
    Nora Cuppens
    Frederic Cuppens
    International Journal of Information Security, 2018, 17 : 83 - 103
  • [32] On Asynchronous Enforcement of Security Policies in "Nomadic" Storage Facilities
    You, Ilsun
    Catuogno, Luigi
    Castiglione, Aniello
    Cattaneo, Giuseppe
    2013 IEEE INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS (ISIE), 2013,
  • [33] Automatic Enforcement of Expressive Security Policies using Enclaves
    Gollamudi, Anitha
    Chong, Stephen
    ACM SIGPLAN NOTICES, 2016, 51 (10) : 494 - 513
  • [34] Compile-time enforcement of dynamic security policies
    Eyers, David M.
    Srinivasan, Sriram
    Moody, Ken
    Bacon, Jean
    2008 IEEE WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2008, : 119 - 126
  • [35] Clusters and security: Distributed security for distributed systems
    Pourzandi, M
    Gordon, D
    Yurcik, W
    Koenig, GA
    2005 IEEE International Symposium on Cluster Computing and the Grid, Vols 1 and 2, 2005, : 96 - 104
  • [36] Semantic Security: Specification and Enforcement of Semantic Policies for Security-driven Collaborations
    Sinnott, R. O.
    Doherty, T.
    Gray, N.
    Lusted, J.
    HEALTHGRID RESEARCH, INNOVATION AND BUSINESS CASE, 2009, 147 : 201 - +
  • [37] Designing, Capturing and Validating History-Sensitive Security Policies for Distributed Systems
    Hernandez, Alejandro Mario
    Nielson, Flemming
    Riis-Nielson, Hanne
    SCIENTIFIC ANNALS OF COMPUTER SCIENCE, 2011, 21 (01) : 107 - 149
  • [38] Static enforcement of security in runtime systems
    Pedersen, Mathias, V
    Askarov, Aslan
    2019 IEEE 32ND COMPUTER SECURITY FOUNDATIONS SYMPOSIUM (CSF 2019), 2019, : 335 - 350
  • [39] Security enforcement in activity management systems
    Karlapalem, K
    Hung, PCK
    WORKFLOW MANAGEMENT SYSTEMS AND INTEROPERABILITY, 1998, 164 : 165 - 194
  • [40] Distributed Middleware Enforcement of Event Flow Security Policy
    Migliavacca, Matteo
    Papagiannis, Ioannis
    Eyers, David M.
    Shand, Brian
    Bacon, Jean
    Pietzuch, Peter
    MIDDLEWARE 2010, 2010, 6452 : 334 - +