DocumentCode :
1911421
Title :
Fine-grain access control for securing shared resources in computational grids
Author :
Butt, A.R. ; Adabala, S. ; Kapadia, N.H. ; Figueiredo, R. ; Fortes, J.A.B.
Author_Institution :
Sch. of Electr. & Comput. Eng., Purdue Univ., West Lafayette, IN, USA
fYear :
2001
fDate :
15-19 April 2001
Abstract :
Computational grids provide computing power by sharing resources across administrative domains. This sharing, coupled with the need to execute untrusted code from arbitrary users, introduces security hazards. This paper addresses the security implications of making a computing resource available to untrusted applications via computational grids. It highlights the problems and limitations of current grid environments and proposes a technique that employs run-time monitoring and a restricted shell. The technique can be used for setting up an execution environment that supports the full legitimate use allowed by the security policy of a shared resource. Performance analysis shows up to 2.14 times execution overhead improvement for shell-based applications. The approach proves effective and provides a substrate for hybrid techniques that combine static and dynamic mechanisms to minimize monitoring overheads.
Keywords :
authorisation; distributed programming; software performance evaluation; system monitoring; Unix access model; administrative domains; computational grids; computing resource availability; dynamic mechanisms; execution environment; execution overhead improvement; fine-grain access control; grid security; hybrid techniques; legitimate use; monitoring overhead minimization; performance analysis; restricted shell; runtime monitoring; security hazards; security policy; shared resource security; shell-based applications; static mechanisms; untrusted code execution; Access control; Authorization; Computer applications; Grid computing; Hazards; Monitoring; Performance analysis; Runtime environment; Security; World Wide Web;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Parallel and Distributed Processing Symposium., Proceedings International, IPDPS 2002, Abstracts and CD-ROM
Conference_Location :
Ft. Lauderdale, FL
Print_ISBN :
0-7695-1573-8
Type :
conf
DOI :
10.1109/IPDPS.2002.1015496
Filename :
1015496
Link To Document :
بازگشت