Virtual Private Services: Coordinated Policy Enforcement for Distributed Applications
نویسندگان
چکیده
Large scale distributed applications combine network access with multiple storage and computational elements. The distributed responsibility for resource control creates new security issues, caused by the complexity of the operating environment. In particular, policies at multiple layers and locations force conventional mechanisms such as firewalls and compartmented file storage into roles where they are clumsy and failure-prone. Our approach relies on two functional divisions. First, we split policy specification and policy enforcement, providing local autonomy within the constraints of the global security policy. Second, we create virtual security domains each with its own security policy. Every domain has an associated set of privileges and permissions restricting it to the resources it needs to use and the services it must perform. Virtual private services ensure security and privacy policies are adhered to through coordinated policy enforcement points.
منابع مشابه
Design and Implementation of Virtual Private Services
Large scale distributed applications such as electronic commerce and online marketplaces (e.g., auction services) combine network access with multiple storage and computational elements. The distributed responsibility for resource control creates new security and privacy issues, caused by the complexity of the operating environment. In particular, policies at multiple layers and locations force...
متن کاملDynamic Operation of Peer-to-Peer Overlay Networks
Virtual overlay networks, such as virtual private networks or peer-to-peer services, can be seen as a new paradigm for providing multi-service networks. Virtual overlay networks may offer customized services to a specified community while providing a high degree of flexibility in the usage of shared resources. This paper examines the requirements of operating dynamic overlays, in particular, fo...
متن کاملDistributed Policy Processing in Virtual Private Operation Environment for Large Scale Networks
VPOE (Virtual Private Operation Environment) is an infrastructure to provide customized services for applications in large-scale heterogeneous networks. In this infrastructure, the programmable network devices called "middleware boxes " can be deployed at some functional locations in the network and provide services eflectively corresponding to the service requirements. The basic functionality ...
متن کاملPolicy and Contract Management for Semantic Web Services
This paper summarizes our efforts to develop capabilities for policy and contract management for Semantic Web Services applications. KAoS services and tools allow for the specification, management, analyzes, disclosure and enforcement of policies represented in OWL. We discuss three current Semantic Web Services applications as examples of the kinds of roles that a policy management framework c...
متن کاملBehavior-based Attestation of Policy Enforcement among Trusted Virtual Domains
With serious situation of data leakage in many enterprises, sensitive dataflow protection based on Trusted Virtual Domains (TVD) has been gradually paid much attention to. Remote attestation among two or more entities across trusted virtual domains is an important means to ensure sensitive dataflow. According to behavior compliance, this paper proposes a behavior-based attestation of policy enf...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- I. J. Network Security
دوره 4 شماره
صفحات -
تاریخ انتشار 2007