Title :
Silver Lining: Enforcing Secure Information Flow at the Cloud Edge
Author :
Khan, Saeed M. ; Hamlen, K.W. ; Kantarcioglu, Murat
Author_Institution :
Dept. of Comput. Sci., Univ. of Texas at Dallas, Richardson, TX, USA
Abstract :
SilverLine is a novel, exceptionally modular framework for enforcing mandatory information flow policies for Java computations on commodity, data-processing, Platform-as-a-Service clouds by leveraging Aspect-Oriented Programming (AOP) and In-lined Reference Monitors (IRMs). Unlike traditional system-level approaches, which typically require modifications to the cloud kernel software, OS/hypervisor, VM, or cloud file system, SilverLine automatically in-lines secure information flow tracking code into untrusted Java binaries as they arrive at the cloud. This facilitates efficient enforcement of a large, flexible class of information flow and mandatory access control policies without any customization of the cloud or its underlying infrastructure. The cloud and the enforcement framework can therefore be maintained completely separately and orthogonally (i.e., modularly). To demonstrate the approach´s feasibility, a prototype implements and deploys SilverLine on a real-world data processing cloud-Hadoop MapReduce. Evaluation results demonstrate that SilverLine provides inter-process information flow security for Hadoop clouds with easy maintainability (through modularity) and low overhead.
Keywords :
aspect-oriented programming; authorisation; cloud computing; parallel programming; AOP; Hadoop MapReduce; IRM; Java binary; Java computations; OS-hypervisor; SilverLine; VM; access control policy; aspect-oriented programming; cloud edge; cloud file system; cloud kernel software; data processing cloud; in-lined reference monitors; information flow policy; inter-process information flow security; operating systems; platform-as-a-service clouds; virtual machines; Access control; Cloud computing; Java; Monitoring; Programming; Runtime; Access control; Aspect-Oriented Programming; Cloud computing; In-lined Reference Monitors; Information flow control; Security;
Conference_Titel :
Cloud Engineering (IC2E), 2014 IEEE International Conference on
Conference_Location :
Boston, MA
DOI :
10.1109/IC2E.2014.83