Virtual Private Services: Coordinated Policy Enforcement for Distributed Applications

نویسندگان

  • Sotiris Ioannidis
  • Steven M. Bellovin
  • John Ioannidis
  • Angelos D. Keromytis
  • Kostas G. Anagnostakis
  • Jonathan M. Smith
چکیده

Large scale distributed applications combine network access with multiple storage and computational elements. The distributed responsibility for resource control creates new security issues, caused by the complexity of the operating environment. In particular, policies at multiple layers and locations force conventional mechanisms such as firewalls and compartmented file storage into roles where they are clumsy and failure-prone. Our approach relies on two functional divisions. First, we split policy specification and policy enforcement, providing local autonomy within the constraints of the global security policy. Second, we create virtual security domains each with its own security policy. Every domain has an associated set of privileges and permissions restricting it to the resources it needs to use and the services it must perform. Virtual private services ensure security and privacy policies are adhered to through coordinated policy enforcement points.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Design and Implementation of Virtual Private Services

Large scale distributed applications such as electronic commerce and online marketplaces (e.g., auction services) combine network access with multiple storage and computational elements. The distributed responsibility for resource control creates new security and privacy issues, caused by the complexity of the operating environment. In particular, policies at multiple layers and locations force...

متن کامل

Dynamic Operation of Peer-to-Peer Overlay Networks

Virtual overlay networks, such as virtual private networks or peer-to-peer services, can be seen as a new paradigm for providing multi-service networks. Virtual overlay networks may offer customized services to a specified community while providing a high degree of flexibility in the usage of shared resources. This paper examines the requirements of operating dynamic overlays, in particular, fo...

متن کامل

Distributed Policy Processing in Virtual Private Operation Environment for Large Scale Networks

VPOE (Virtual Private Operation Environment) is an infrastructure to provide customized services for applications in large-scale heterogeneous networks. In this infrastructure, the programmable network devices called "middleware boxes " can be deployed at some functional locations in the network and provide services eflectively corresponding to the service requirements. The basic functionality ...

متن کامل

Policy and Contract Management for Semantic Web Services

This paper summarizes our efforts to develop capabilities for policy and contract management for Semantic Web Services applications. KAoS services and tools allow for the specification, management, analyzes, disclosure and enforcement of policies represented in OWL. We discuss three current Semantic Web Services applications as examples of the kinds of roles that a policy management framework c...

متن کامل

Behavior-based Attestation of Policy Enforcement among Trusted Virtual Domains

With serious situation of data leakage in many enterprises, sensitive dataflow protection based on Trusted Virtual Domains (TVD) has been gradually paid much attention to. Remote attestation among two or more entities across trusted virtual domains is an important means to ensure sensitive dataflow. According to behavior compliance, this paper proposes a behavior-based attestation of policy enf...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • I. J. Network Security

دوره 4  شماره 

صفحات  -

تاریخ انتشار 2007