24th IEEE Symposium on Reliable Distributed Systems (SRDS'05) Enforcing Enterprise-wide Policies Over Standard Client-Server Interactions Orlando, Florida October 26-October 28 ISBN: 0-7695-2463-X
We propose and evaluate a novel framework for enforcing global coordination and control policies over interacting software components in enterprise computing environments. This framework combines a per-node reference monitor with two existing coordination and control systems to enforce policies that, among other properties, are stateful and communal. Each reference monitor filters messages exchanged between the interacting software components similar to a firewall, passing only messages that are allowed by the policies in effect. This filtering approach decouples coordination and control from application implementation, allowing the coordination and control mechanism and application implementations to evolve independently of each other. We demonstrate the power of our framework by using it to specify and enforce an RBAC policy with delegation, revocation, and separation-of-duty over accesses to a cluster of NFS and SMB file servers without changing any client or server implementations. Measurements show that our framework imposes acceptable overheads when enforcing this policy.
Citation:
Zhijun He, Tuan Phan, Thu D. Nguyen, "Enforcing Enterprise-wide Policies Over Standard Client-Server Interactions," srds, pp.119-131, 24th IEEE Symposium on Reliable Distributed Systems (SRDS'05), 2005 Usage of this product signifies your acceptance of the Terms of Use. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||