Using a virtual machine to protect sensitive Grid resources

نویسندگان

  • Xin Zhao
  • Kevin Borders
  • Atul Prakash
چکیده

Most Grid systems rely on their operating systems (OSs) to protect their sensitive files and networks. Unfortunately, modern OSs are very complex and it is difficult to completely avoid intrusions. Once intruders compromise the OS and gain system privilege, they can easily disable or bypass the OS security protections. This paper proposes a secure virtual Grid system, SVGrid, to protect sensitive system resources. SVGrid works by isolating Grid applications in Grid virtual machines. The Grid virtual machines’ filesystem and network services are moved into a dedicated monitor virtual machine. All file and network accesses are forced to go through this monitor virtual machine, where SVGrid checks request parameters and only accepts the requests that comply with security rules. Because SVGrid enforces security policy in the isolated monitor virtual machine, it can continue to protect sensitive files and networks even if a Grid virtual machine is compromised. We tested SVGrid against attacks on Grid virtual machines. SVGrid was able to prevent all of them from accessing files and networks maliciously. We also evaluated the performance of SVGrid and found that performance cost was reasonable considering the security benefits of SVGrid. Furthermore, the experimental results show that the virtual remote procedure call mechanism proposed in this paper significantly improves system performance. Copyright c © 2006 John Wiley & Sons, Ltd.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Harmony: A Desktop Grid for Delivering Enterprise Computations

This paper describes Harmony, a practical grid infrastructure built using personal computer resources. Harmony addresses the key concerns of end users for responsiveness, privacy and protection by isolating the grid computation in a virtual machine on the PC and by implementing a layered resource management architecture to divert workload to unutilized computers from those currently experiencin...

متن کامل

Division of Labor: Tools for Growing and Scaling Grids

To enable Grid scalability and growth, a usage model has evolved whereby resource providers make resources available not to individual users directly, but rather to larger units, called virtual organizations. In this paper, we describe abstractions that allow resource providers to delegate the usage of remote resources dynamically to virtual organizations in applicationindependent ways, and pre...

متن کامل

Grid Virtualization Engine: Providing Virtual Resources for Grid Infrastructure

Virtual machines offer a lot of advantage such as easy configuration and management and can simplify the development and the deployment of Grid infrastructures. Various virtualization implementations despite have similar functions often provide different management and access interfaces. The heterogeneous virtualization technologies bring challenges for employing virtual machine as computing re...

متن کامل

Determining the Optimal Strategy of Multi Virtual Power Plants using GA-GT

abstract: In the present work, determining the optimal strategy(profit based) of multi virtual power plants (VPPs) as well as the objective of maximizing profit through the multi-level control of VPPs are discussed by the micro-grid utilization center including virtual power plants. VPPs include renewable resources such as wind farms, photovoltaic, and conventional resources such as fuel cell, ...

متن کامل

Editorial Semantics , Resource and Grid

The future interconnection environment will be a platform-independent Virtual Grid consisting of requirements, roles and resources. With machine-understandable semantics, a resource can actively and dynamically cluster relevant resources to provide on-demand services by understanding requirements and functions each other. Versatile resources are encapsulated to provide services in the form of s...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Concurrency and Computation: Practice and Experience

دوره 19  شماره 

صفحات  -

تاریخ انتشار 2007