loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Sixth IEEE International Symposium on Cluster Computing and the Grid Workshops (CCGRIDW'06)
Segregate Applications at System Level to Eliminate Security Problems
Singapore
May 16-May 19
ISBN: 0-7695-2585-7
Chu J. Jong, Illinois State University, USA
Improvements in advanced microprocessor design and cost/performance gains in hardware technology have changed the distributed computing paradigm from a homogeneous parallel computation to a heterogeneous cluster one. This new paradigm involves coordinating and sharing computing, application, data, storage, and network resources across dynamic and possibly geographically dispersed organizations. To attract organizations to take advantage of off-the-shelf ready-to-build commodity clusters, substantial improvements have been realized in many areas such as resource allocation and management, process distribution and recovery, data integrity and application security. However, the primary factor above all others as we approach this new level of computing is trust - higher confidence in the privacy and security of data and resources is needed to advance to the next level. Most organizations avoid running applications using their private data on systems that are not under their control until a sufficient confidence of trust is built. Proofs of information security help build a higher level of trust and thus increase the utilization of the shared cluster.

When launch applications on computer systems, five potential security threats arise at user, protocol, system, communication and hardware levels. To secure information, each level has to execute a set of protection tasks. Full trust will be achieved after all levels are proven immune from attack. In a conventional system, security is guaranteed if the hosting system is wholly controlled by the applications. Therefore, to protect confidential data between applications in a shared system, the traditional approach is to separate the entire system by either spatial or time methods. Here we introduce a resource separating and grouping mechanism that physically and logically separates system resources by adaptable scale to eliminate security problems and reduce the overall cost.

Index Terms:
data security, resource management, virtual machines
Citation:
Chu J. Jong, "Segregate Applications at System Level to Eliminate Security Problems," ccgrid, vol. 2, pp.31, Sixth IEEE International Symposium on Cluster Computing and the Grid Workshops (CCGRIDW'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.