DocumentCode
2907842
Title
Authorizing Remote Job Execution Based on Job Properties
Author
Park, Sang-Min ; Wasson, Glenn ; Humphrey, Marty
Author_Institution
University of Virginia, USA
fYear
2006
fDate
Dec. 2006
Firstpage
29
Lastpage
29
Abstract
E-Science often requires access to remote Grid computing platforms. Current authorization systems on these remote systems have largely based decisions solely on the identity of the submitter -- the job is permitted to execute on the local resource if the job originates from an authenticated and authorized end-user. The problem with this approach is that there is no consideration to what the job will/should do when executed, so an errorful or malicious job -- even from what purports to be a trusted user -- can create significant damage before an operator notices and can kill or suspend the job. This paper presents a novel end-to-end job execution framework in which the properties (behavior) of the job are taken into account for the authorization decision. Experimental results show the duration to perform the authorization and to establish a subsequent restrictive execution context is sufficiently low -- our observed overhead of 253.1 ms on commodity hardware is an acceptable cost for most Grid applications to pay to achieve this more secure execution environment.
Keywords
Authorization; Computer science; Control systems; Costs; File systems; Grid computing; Hardware; Job design; Permission; Sockets;
fLanguage
English
Publisher
ieee
Conference_Titel
e-Science and Grid Computing, 2006. e-Science '06. Second IEEE International Conference on
Conference_Location
Amsterdam, The Netherlands
Print_ISBN
0-7695-2734-5
Type
conf
DOI
10.1109/E-SCIENCE.2006.261113
Filename
4031002
Link To Document