Sciweavers

SRDS
2005
IEEE

Enforcing Enterprise-wide Policies Over Standard Client-Server Interactions

13 years 10 months ago
Enforcing Enterprise-wide Policies Over Standard Client-Server Interactions
We propose and evaluate a novel framework for enforcing global coordination and control policies over interacting software components in enterprise computing environments. This framework combines a per-node reference monitor with two existing coordination and control systems to enforce policies that, among other properties, are stateful and communal. Each reference monitor filters messages exchanged between the interacting software components similar to a firewall, passing only messages that are allowed by the policies in effect. This filtering approach decouples coordination and control from application implementation, allowing the coordination and control mechanism and application implementations to evolve independently of each other. We demonstrate the power of our framework by using it to specify and enforce an RBAC policy with delegation, revocation, and separation-of-duty over accesses to a cluster of NFS and SMB file servers without changing any client or server implementati...
Zhijun He, Tuan Phan, Thu D. Nguyen
Added 25 Jun 2010
Updated 25 Jun 2010
Type Conference
Year 2005
Where SRDS
Authors Zhijun He, Tuan Phan, Thu D. Nguyen
Comments (0)