DocumentCode :
2231284
Title :
Security and Integrity of a Distributed File Storage in a Virtual Environment
Author :
Sala, Gaspare ; Sgandurra, Daniele ; Baiardi, Fabrizio
Author_Institution :
Univ. di Pisa, Pisa
fYear :
2007
fDate :
27-27 Sept. 2007
Firstpage :
58
Lastpage :
69
Abstract :
Virtual environment secure file system (VSFS) is a software architecture for secure file sharing among applications with different trust levels that consists of a set of interconnected virtual machines (VMs). Application VMs (APP-VMs) run the application processes that transparently access remote shared files hosted by file system VMs (FS-VMs). Each FS-VM implements a mandatory access control (MAC) security policy to control file sharing. To define and enforce this policy, VSFS uses SELinux. Each APP-VM is labeled with a security context paired with the IP address of the VM. FS-VMs use this context to check access rights of the APP-VMs with respect to the requested files and operations. A third set of VMs, the administrative VMs (A-VMs), provides assurance about the integrity of the FS-VMs and implements anti-spoofing techniques to authenticate each file request sent by the APP-VMs. After describing the overall architecture, we discuss the security and performance results of a first prototype. These first results show that the overhead due to mandatory access control is fairly acceptable.
Keywords :
Linux; access control; file organisation; security of data; software architecture; virtual machines; SELinux; distributed file storage; file sharing; interconnected virtual machines; mandatory access control security policy; software architecture; virtual environment secure file system; Access control; Application software; File systems; Peer to peer computing; Secure storage; Security; Software architecture; Virtual environment; Virtual machining; Voice mail; introspection; mandatory access control; network file system; trust level; virtual machines;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security in Storage Workshop, 2007. SISW '07. Fourth International IEEE
Conference_Location :
San Diego, CA
Print_ISBN :
978-0-7695-3052-9
Type :
conf
DOI :
10.1109/SISW.2007.10
Filename :
4389745
Link To Document :
بازگشت