Unified Platform for Secure Networked Information Systems
نویسندگان
چکیده
In this paper, we present a unified declarative platform for specifying, implementing, analyzing and auditing large-scale secure information systems. Our proposed system builds upon techniques from logic-based trust management systems, declarative networking, and data analysis via provenance. First, we propose the Secure Network Datalog (SeNDlog) language that unifies Binder, a logic-based language for access control in distributed systems, and Network Datalog (NDlog), a distributed recursive query language for declarative networks. SeNDlog enables network routing, information systems, and their security policies to be specified and implemented within a common declarative framework. Second, we extend existing distributed recursive query processing techniques to execute SeNDlog programs that incorporate the notion of authenticated communication among untrusted nodes. Third, we demonstrate that an integrated declarative framework enables cross-layer analysis and auditing via the use of distributed network provenance. Finally, using a local cluster and the PlanetLab testbed, we perform a detailed performance study of a variety of declarative secure networked information systems implemented using our platform. We further perform an evaluation of network provenance via a SeNDlog-based packet tracing service within a local cluster. Comments University of Pennsylvania Department of Computer and Information Science Technical Report No. MSCIS-08-05 This technical report is available at ScholarlyCommons: http://repository.upenn.edu/cis_reports/872 Unified Platform for Secure Networked Information Systems Wenchao Zhou∗ Yun Mao∗ Boon Thau Loo∗ Martı́n Abadi†‡ ∗University of Pennsylvania †UC Santa Cruz ‡Microsoft Research {wenchaoz, maoy, boonloo}@cis.upenn.edu, [email protected]
منابع مشابه
Unified Declarative Platform for Secure Networked Information Systems
We present a unified declarative platform for specifying, implementing, and analyzing secure networked information systems. Our work builds upon techniques from logic-based trust management systems, declarative networking, and data analysis via provenance. We make the following contributions. First, we propose the secure network datalog (SeNDlog) language that unifies Binder, a logic-based lang...
متن کاملDeveloping Secure Networked Web-Based Systems Using Model-based Risk Assessment and UMLsec
Despite a growing awareness of security issues in networked computing systems, most development processes used today still do not take security aspects into account. To address this problem, we designed a process for developing secure networked systems based on the extension of the Unified Modeling Language (UML) for secure systems development UMLsec and on the concept of model-based risk asses...
متن کاملNano-gels: A versatile nano -carrier platform for drug delivery systems: A mini review
Nowadays the application of nanotechnology in different biomedical fields such as drug delivery is increasing due to its unique advantages. With this in mind, it is widely believed that nanogels as the nanometer-sized networked polymeric particles have a considerable impact on drug delivery systems as biocompatible nanocarriers due to their unique characteristics such as high loading capacity, ...
متن کاملDesigninga Neuro-Sliding Mode Controller for Networked Control Systems with Packet Dropout
This paper addresses control design in networked control system by considering stochastic packet dropouts in the forward path of the control loop. The packet dropouts are modelled by mutually independent stochastic variables satisfying Bernoulli binary distribution. A sliding mode controller is utilized to overcome the adverse influences of stochastic packet dropouts in networked control system...
متن کاملModelling and Compensation of uncertain time-delays in networked control systems with plant uncertainty using an Improved RMPC Method
Control systems with digital communication between sensors, controllers and actuators are called as Networked Control Systems (NCSs). In general, NCSs encounter with some problems such as packet dropouts and network induced delays. When plant uncertainty is added to the aforementioned problems, the design of the robust controller that is able to guarantee the stability, becomes more complex. In...
متن کامل