• DocumentCode
    1804570
  • Title

    FileWall: A Firewall for Network File Systems

  • Author

    Smaldone, Stephen ; Bohra, Aniruddha ; Iftode, Liviu

  • Author_Institution
    Rutgers Univ., Piscataway
  • fYear
    2007
  • fDate
    25-26 Sept. 2007
  • Firstpage
    153
  • Lastpage
    162
  • Abstract
    Access control in network file systems relies on primitive mechanisms like access control lists and permission bits, which are not enough when operating in a hostile network environment. Network middleboxes, e.g., firewalls, completely ignore file system semantics when defining policies. Therefore, implementing simple context-aware access policies requires modifications to file servers and/or clients, which is impractical. We present FileWall, a network middlebox that allows administrators to define context-aware access policies for file systems using both the network context and the file system context. FileWall interposes on the client-server network path and implements administrator defined policies through message transformation without modifying either clients or servers. In this paper, we present the design and implementation of FileWall for the NFS protocol. Our evaluation demonstrates that FileWall imposes minimal overheads for common file system operations, even under heavy loads.
  • Keywords
    authorisation; client-server systems; file organisation; ubiquitous computing; access control; client-server network path; context-aware access policies; firewall; network file systems; Access control; Context awareness; File servers; File systems; Middleboxes; Monitoring; Network servers; Permission; Protection; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable, Autonomic and Secure Computing, 2007. DASC 2007. Third IEEE International Symposium on
  • Conference_Location
    Columbia, MD
  • Print_ISBN
    978-0-7695-2985-1
  • Type

    conf

  • DOI
    10.1109/DASC.2007.27
  • Filename
    4351400