Using a virtual machine to protect sensitive Grid resources
نویسندگان
چکیده
Most Grid systems rely on their operating systems (OSs) to protect their sensitive files and networks. Unfortunately, modern OSs are very complex and it is difficult to completely avoid intrusions. Once intruders compromise the OS and gain system privilege, they can easily disable or bypass the OS security protections. This paper proposes a secure virtual Grid system, SVGrid, to protect sensitive system resources. SVGrid works by isolating Grid applications in Grid virtual machines. The Grid virtual machines’ filesystem and network services are moved into a dedicated monitor virtual machine. All file and network accesses are forced to go through this monitor virtual machine, where SVGrid checks request parameters and only accepts the requests that comply with security rules. Because SVGrid enforces security policy in the isolated monitor virtual machine, it can continue to protect sensitive files and networks even if a Grid virtual machine is compromised. We tested SVGrid against attacks on Grid virtual machines. SVGrid was able to prevent all of them from accessing files and networks maliciously. We also evaluated the performance of SVGrid and found that performance cost was reasonable considering the security benefits of SVGrid. Furthermore, the experimental results show that the virtual remote procedure call mechanism proposed in this paper significantly improves system performance. Copyright c © 2006 John Wiley & Sons, Ltd.
منابع مشابه
Harmony: A Desktop Grid for Delivering Enterprise Computations
This paper describes Harmony, a practical grid infrastructure built using personal computer resources. Harmony addresses the key concerns of end users for responsiveness, privacy and protection by isolating the grid computation in a virtual machine on the PC and by implementing a layered resource management architecture to divert workload to unutilized computers from those currently experiencin...
متن کاملDivision of Labor: Tools for Growing and Scaling Grids
To enable Grid scalability and growth, a usage model has evolved whereby resource providers make resources available not to individual users directly, but rather to larger units, called virtual organizations. In this paper, we describe abstractions that allow resource providers to delegate the usage of remote resources dynamically to virtual organizations in applicationindependent ways, and pre...
متن کاملGrid Virtualization Engine: Providing Virtual Resources for Grid Infrastructure
Virtual machines offer a lot of advantage such as easy configuration and management and can simplify the development and the deployment of Grid infrastructures. Various virtualization implementations despite have similar functions often provide different management and access interfaces. The heterogeneous virtualization technologies bring challenges for employing virtual machine as computing re...
متن کاملDetermining the Optimal Strategy of Multi Virtual Power Plants using GA-GT
abstract: In the present work, determining the optimal strategy(profit based) of multi virtual power plants (VPPs) as well as the objective of maximizing profit through the multi-level control of VPPs are discussed by the micro-grid utilization center including virtual power plants. VPPs include renewable resources such as wind farms, photovoltaic, and conventional resources such as fuel cell, ...
متن کاملEditorial Semantics , Resource and Grid
The future interconnection environment will be a platform-independent Virtual Grid consisting of requirements, roles and resources. With machine-understandable semantics, a resource can actively and dynamically cluster relevant resources to provide on-demand services by understanding requirements and functions each other. Versatile resources are encapsulated to provide services in the form of s...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Concurrency and Computation: Practice and Experience
دوره 19 شماره
صفحات -
تاریخ انتشار 2007