DocumentCode :
3121573
Title :
Unified Declarative Platform for Secure Netwoked Information Systems
Author :
Zhou, Wenchao ; Mao, Yun ; Loo, Boon Thau ; Abadi, Martín
Author_Institution :
Univ. of Pennsylvania, Philadelphia, PA
fYear :
2009
fDate :
March 29 2009-April 2 2009
Firstpage :
150
Lastpage :
161
Abstract :
We present a unified declarative platform for specifying, implementing, and analyzing secure networked information systems. Our work builds upon techniques from logic-based trust management systems, declarative networking, and data analysis via provenance. We make the following contributions. First, we propose the secure network datalog (SeNDlog) language that unifies Binder, a logic-based language for access control in distributed systems, and Network Datalog, a distributed recursive query language for declarative networks. SeNDlog enables network routing, information systems, and their security policies to be specified and implemented within a common declarative framework. Second, we extend existing distributed recursive query processing techniques to execute SeNDlog programs that incorporate authenticated communication among untrusted nodes. Third, we demonstrate that distributed network provenance can be supported naturally within our declarative framework for network security analysis and diagnostics. Finally, using a local cluster and the PlanetLab testbed, we perform a detailed performance study of a variety of secure networked systems implemented using our platform.
Keywords :
authorisation; data analysis; distributed processing; information systems; query languages; query processing; telecommunication network routing; Binder; PlanetLab testbed; SeNDlog programs; access control; data analysis; declarative networking; distributed recursive query language; distributed systems; logic-based trust management systems; network datalog; network routing; network security analysis; secure network datalog language; secure networked information systems; unified declarative platform; Access control; Communication system security; Data analysis; Data security; Database languages; Information analysis; Information security; Information systems; Management information systems; Routing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Data Engineering, 2009. ICDE '09. IEEE 25th International Conference on
Conference_Location :
Shanghai
ISSN :
1084-4627
Print_ISBN :
978-1-4244-3422-0
Electronic_ISBN :
1084-4627
Type :
conf
DOI :
10.1109/ICDE.2009.58
Filename :
4812399
Link To Document :
بازگشت