Design and Implementation of Virtual Private Services

نویسندگان

  • Sotiris Ioannidis
  • Steven M. Bellovin
  • John Ioannidis
  • Angelos D. Keromytis
  • Jonathan M. Smith
چکیده

Large scale distributed applications such as electronic commerce and online marketplaces (e.g., auction services) combine network access with multiple storage and computational elements. The distributed responsibility for resource control creates new security and privacy issues, caused by the complexity of the operating environment. In particular, policies at multiple layers and locations force conventional mechanisms such as firewalls and compartmented file storage into roles where they are clumsy and failure-prone. We propose a new approach, virtual private services. Our approach relies on two functional divisions. First, we split policy specification and policy enforcement, providing local autonomy within the constraints of the global security policy. Second, we create virtual security domains each with its own security policy. Every domain has an associated set of privileges and permissions restricting it to the resources it needs to use and the services it must perform. Virtual private services ensure security and privacy policies are adhered to by coordinating policy enforcement points. Our prototype implementation under OpenBSD demonstrates low performance overhead on a variety of latencyand throughput-oriented microand macrobenchmarks.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

الگوهای «مشارکت دولتی- خصوصی» و اثر آنها بر شاخص‌های میانی بیمارستان: یک مرور انتقادی

Introduction: Public-private partnership can help governments deal with resource constraints in their health sectors. The aim of this study was to investigate the effects of different models of public-private partnership on hospital mid-indicators and identify factors affecting its successful implementation. Methods: This critical review was conducted from 2000 to 2017. Databases, such as Goog...

متن کامل

Determining Components of Medical Instructional Design based on Virtual Reality by Research Synthesis

Introduction: The purpose of the present study was to determine the components of medical education design based on virtual reality by research synthesis method. Methods: In the present study a synthesis method was used. In order to study the research background and to collect appropriate data among the databases of Science Direct, Springer, Scopus, ProQuest and Eric (ERIC) search. With the ke...

متن کامل

Designing a Public-Private Partnership Model for Public Hospitals in Iran

Background and Objectives: Public-Private Partnership (PPP) is a well-established model to alleviate the risk of investment in health domain. While the model is widely applied in the developed countries, the adoption of the model in many developing countries is hampered partly by the lack of knowledge on dimensions and requirements of its local implementation. The present study...

متن کامل

Automated Negotiation for Provisioning Virtual Private Networks using FIPA-Compliant Agents

This paper describes the design and implementation of negotiating agents for the task of provisioning virtual private networks. The agents and their interactions comply with the FIPA specification and they are implemented using the FIPA -OS agent framework. Particular attention is focused on the design and implementation of the negotiation algorithms.

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2003