Deploy, Adjust and Readjust: Supporting Dynamic Reconfiguration of Policy Enforcement

Abstract : For large distributed applications, security and performance are two requirements often difficult to satisfy together. Addressing them separately leads more often to fast systems with security holes, rather than secure systems with poor performance. For instance, caching data needed for security decisions can lead to security violations when the data changes faster than the cache can refresh it. Retrieving such fresh data without caching it impacts performance. In this paper, we analyze a subproblem: how to dynamically configure a distributed authorization system when both security and performance requirements change. We examine data caching, retrieval and correlation, and propose a runtime management tool that, with external input, finds and enacts the customizations that satisfy both security and performance needs. Preliminary results show it takes around two seconds to find customization solutions in a setting with over one thousand authorization components.
Type de document :
Communication dans un congrès
Fabio Kon; Anne-Marie Kermarrec. 12th International Middleware Conference (MIDDLEWARE), Dec 2011, Lisbon, Portugal. Springer, Lecture Notes in Computer Science, LNCS-7049, pp.350-369, 2011, Middleware 2011. 〈10.1007/978-3-642-25821-3_18〉
Liste complète des métadonnées

Littérature citée [25 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01597755
Contributeur : Hal Ifip <>
Soumis le : jeudi 28 septembre 2017 - 17:11:04
Dernière modification le : jeudi 28 septembre 2017 - 17:16:56
Document(s) archivé(s) le : vendredi 29 décembre 2017 - 16:19:30

Fichier

978-3-642-25821-3_18_Chapter.p...
Fichiers produits par l'(les) auteur(s)

Licence


Distributed under a Creative Commons Paternité 4.0 International License

Identifiants

Citation

Gabriela Gheorghe, Bruno Crispo, Roberto Carbone, Lieven Desmet, Wouter Joosen. Deploy, Adjust and Readjust: Supporting Dynamic Reconfiguration of Policy Enforcement. Fabio Kon; Anne-Marie Kermarrec. 12th International Middleware Conference (MIDDLEWARE), Dec 2011, Lisbon, Portugal. Springer, Lecture Notes in Computer Science, LNCS-7049, pp.350-369, 2011, Middleware 2011. 〈10.1007/978-3-642-25821-3_18〉. 〈hal-01597755〉

Partager

Métriques

Consultations de la notice

11

Téléchargements de fichiers

4