FileWall: Implementing File Access Policies using Dynamic Access Context
نویسندگان
چکیده
FileWall is a file access control framework that allows file system administrators to enforce file access policies based on dynamic access context such as access history, environment, etc. Similar to a firewall, which interposes on a network path and operates on packets to enforce network access policies, FileWall interposes on a client-server path and operates on network file system messages to enforce file access policies. FileWall does not require any modification to either the file system client or the file server, while minimizing the non-recoverable state. FileWall provides the administrator with the ability to protect file systems, provide quality of service, perform forensic analysis, and other file access policies. A FileWall prototype has been implemented using the Click modular router and the SFS file system toolkit. This prototype is evaluated by interposing between NFS clients and servers. Performance evaluation shows that FileWall introduces minimal interposition overhead and maintains close to 90% throughput compared to NFS. Two real world case studies demonstrate that FileWall can perform effective flash crowd mitigation on a web server, and provide QoS to clients by prioritizing file system requests and responses.
منابع مشابه
Implementing Network File System Policies with FileWall
Managing network file systems in large deployments is a critical challenge facing administrators today. Network file systems are widely used, are standardized, and provide acceptable performance. These systems are designed for the least common denominator of functionality, across all deployments to enable widespread use across diverse client systems. Unfortunately, specific deployment scenarios...
متن کاملA semantic-aware role-based access control model for pervasive computing environments
Access control in open and dynamic Pervasive Computing Environments (PCEs) is a very complex mechanism and encompasses various new requirements. In fact, in such environments, context information should be used in access control decision process; however, it is not applicable to gather all context information completely and accurately all the time. Thus, a suitable access control model for PCEs...
متن کاملCAMAC: a context-aware mandatory access control model
Mandatory access control models have traditionally been employed as a robust security mechanism in multilevel security environments such as military domains. In traditional mandatory models, the security classes associated with entities are context-insensitive. However, context-sensitivity of security classes and flexibility of access control mechanisms may be required especially in pervasive c...
متن کاملA context-sensitive dynamic role-based access control model for pervasive computing environments
Resources and services are accessible in pervasive computing environments from anywhere and at any time. Also, due to ever-changing nature of such environments, the identity of users is unknown. However, users must be able to access the required resources based on their contexts. These and other similar complexities necessitate dynamic and context-aware access control models for such environmen...
متن کاملImproving Data Grids Performance by Using Modified Dynamic Hierarchical Replication Strategy
Abstract: A Data Grid connects a collection of geographically distributed computational and storage resources that enables users to share data and other resources. Data replication, a technique much discussed by Data Grid researchers in recent years creates multiple copies of file and places them in various locations to shorten file access times. In this paper, a dynamic data replication strate...
متن کامل