DocumentCode :
244062
Title :
Silver Lining: Enforcing Secure Information Flow at the Cloud Edge
Author :
Khan, Saeed M. ; Hamlen, K.W. ; Kantarcioglu, Murat
Author_Institution :
Dept. of Comput. Sci., Univ. of Texas at Dallas, Richardson, TX, USA
fYear :
2014
fDate :
11-14 March 2014
Firstpage :
37
Lastpage :
46
Abstract :
SilverLine is a novel, exceptionally modular framework for enforcing mandatory information flow policies for Java computations on commodity, data-processing, Platform-as-a-Service clouds by leveraging Aspect-Oriented Programming (AOP) and In-lined Reference Monitors (IRMs). Unlike traditional system-level approaches, which typically require modifications to the cloud kernel software, OS/hypervisor, VM, or cloud file system, SilverLine automatically in-lines secure information flow tracking code into untrusted Java binaries as they arrive at the cloud. This facilitates efficient enforcement of a large, flexible class of information flow and mandatory access control policies without any customization of the cloud or its underlying infrastructure. The cloud and the enforcement framework can therefore be maintained completely separately and orthogonally (i.e., modularly). To demonstrate the approach´s feasibility, a prototype implements and deploys SilverLine on a real-world data processing cloud-Hadoop MapReduce. Evaluation results demonstrate that SilverLine provides inter-process information flow security for Hadoop clouds with easy maintainability (through modularity) and low overhead.
Keywords :
aspect-oriented programming; authorisation; cloud computing; parallel programming; AOP; Hadoop MapReduce; IRM; Java binary; Java computations; OS-hypervisor; SilverLine; VM; access control policy; aspect-oriented programming; cloud edge; cloud file system; cloud kernel software; data processing cloud; in-lined reference monitors; information flow policy; inter-process information flow security; operating systems; platform-as-a-service clouds; virtual machines; Access control; Cloud computing; Java; Monitoring; Programming; Runtime; Access control; Aspect-Oriented Programming; Cloud computing; In-lined Reference Monitors; Information flow control; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cloud Engineering (IC2E), 2014 IEEE International Conference on
Conference_Location :
Boston, MA
Type :
conf
DOI :
10.1109/IC2E.2014.83
Filename :
6903456
Link To Document :
بازگشت