DocumentCode :
2539605
Title :
Enforcing enterprise-wide policies over standard client-server interactions
Author :
He, Zhijun ; Phan, Tuan ; Nguyen, Thu D.
Author_Institution :
Dept. of Comput. Sci., Rutgers Univ., NJ, USA
fYear :
2005
fDate :
26-28 Oct. 2005
Firstpage :
119
Lastpage :
130
Abstract :
We propose and evaluate a novel framework for enforcing global coordination and control policies over interacting software components in enterprise computing environments. This framework combines a per-node reference monitor with two existing coordination and control systems to enforce policies that, among other properties, are stateful and communal. Each reference monitor filters messages exchanged between the interacting software components similar to a firewall, passing only messages that are allowed by the policies in effect. This filtering approach decouples coordination and control from application implementation, allowing the coordination and control mechanism and application implementations to evolve independently of each other. We demonstrate the power of our framework by using it to specify and enforce an RBAC policy with delegation, revocation, and separation-of-duty over accesses to a cluster of NFS and SMB file servers without changing any client or server implementations. Measurements show that our framework imposes acceptable overheads when enforcing this policy.
Keywords :
authorisation; client-server systems; file servers; message passing; object-oriented programming; NFS file servers; RBAC policy; SMB file servers; client-server interactions; enterprise computing environments; enterprise-wide policy enforcement; per-node reference monitor; software component interaction; Access control; Application software; Computer science; Computerized monitoring; Control systems; File servers; Filtering; Filters; Helium; Protocols;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Reliable Distributed Systems, 2005. SRDS 2005. 24th IEEE Symposium on
Print_ISBN :
0-7695-2463-X
Type :
conf
DOI :
10.1109/RELDIS.2005.17
Filename :
1541190
Link To Document :
بازگشت