sfatables: A Firewall-like Policy Engine for Federated Systems

S. Bhatia, A. Bavier, L. Peterson, Soner Sevinc
{"title":"sfatables: A Firewall-like Policy Engine for Federated Systems","authors":"S. Bhatia, A. Bavier, L. Peterson, Soner Sevinc","doi":"10.1109/ICDCS.2011.58","DOIUrl":null,"url":null,"abstract":"Recent efforts to federate computation and communication resources across organizational boundaries face a challenge in establishing the policies by which one organization's users can access resources in other organizations. This paper describes an approach to defining, communicating, analyzing, and enforcing resource allocation policies in this new setting. Our approach was designed to address the needs of Planet Lab, but we demonstrate through a range of examples that it is general enough to accommodate a diverse collection of computing facilities. Our policy engine is implemented in a specific tool chain, called {\\tt sfatables}, that is patterned after the {\\tt iptables} mechanism used to define packet processing policies for network traffic. The interface to our policy engine thus uses the familiar paradigm of a {\\tt firewall} and provides a flexible interface for resource owners to specify access policies for their resources. Our implementation makes it possible to precisely document policies, query, and analyze them.","PeriodicalId":6300,"journal":{"name":"2012 IEEE 32nd International Conference on Distributed Computing Systems","volume":"3 2 1","pages":"467-476"},"PeriodicalIF":0.0000,"publicationDate":"2011-06-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 IEEE 32nd International Conference on Distributed Computing Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICDCS.2011.58","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Recent efforts to federate computation and communication resources across organizational boundaries face a challenge in establishing the policies by which one organization's users can access resources in other organizations. This paper describes an approach to defining, communicating, analyzing, and enforcing resource allocation policies in this new setting. Our approach was designed to address the needs of Planet Lab, but we demonstrate through a range of examples that it is general enough to accommodate a diverse collection of computing facilities. Our policy engine is implemented in a specific tool chain, called {\tt sfatables}, that is patterned after the {\tt iptables} mechanism used to define packet processing policies for network traffic. The interface to our policy engine thus uses the familiar paradigm of a {\tt firewall} and provides a flexible interface for resource owners to specify access policies for their resources. Our implementation makes it possible to precisely document policies, query, and analyze them.
stabables:联邦系统的类似防火墙的策略引擎
最近跨组织边界联合计算和通信资源的工作面临着一个挑战,即建立一个组织的用户可以访问其他组织中的资源的策略。本文描述了在这种新设置中定义、交流、分析和执行资源分配策略的方法。我们的方法是为了满足Planet Lab的需求而设计的,但是我们通过一系列示例来证明,它足以适应各种计算设施的集合。我们的策略引擎是在一个特定的工具链中实现的,这个工具链被称为{\tt tables},它是按照用于定义网络流量的数据包处理策略的{\tt iptables}机制设计的。因此,我们的策略引擎的接口使用了我们熟悉的{\tt防火墙}范例,并为资源所有者提供了一个灵活的接口来为他们的资源指定访问策略。我们的实现使得精确地记录策略、查询和分析它们成为可能。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信