Evaluating Grid Portal Security

Evaluating Grid Portal Security
复制标题

评估网格门户安全

DOI:
--
复制
发表时间:
2006
期刊:
International Conference on Software Composition
影响因子:
--
通讯作者:
M. Humphrey
M. Humphrey
中科院分区:
--
文献类型:
--
作者:
D. Vecchio;Victor Hazlewood;M. Humphrey

文献摘要

被引文献

相似文献

网格门户是一种日益流行的机制,用于为网格服务和资源创建可定制的、基于 Web 的界面。由于网格技术强大的通用性质,此类资源的任何门户或入口点的安全性都不能掉以轻心。如果门户在可信边界内运行,例如在 SDSC 计算机上运行以访问 TeraGrid 的科学网关,则尤其如此。为了评估网格门户安全的现状,我们对作为 TeraGrid 前端的三个最流行的网格门户框架进行了比较分析:GridSphere、OGCE 和 clarens。我们探讨网格门户在身份验证(包括用户识别)、授权、审计(日志记录)和会话管理领域面临的一般挑战,然后对比不同网格门户实现如何应对这些挑战。我们发现,尽管大多数网格门户在一定程度上解决了这些安全问题,但仍然存在改进的空间,特别是在安全默认配置以及全面的日志记录和审计支持方面。最后,我们提出了设计、实施和配置安全网格门户的具体建议
Grid portals are an increasingly popular mechanism for creating customizable, Web-based interfaces to grid services and resources. Due to the powerful, general-purpose nature of grid technology, the security of any portal or entry point to such resources cannot be taken lightly. This is particularly true if the portal is running inside of a trusted perimeter, such as a science gateway running on an SDSC machine for access to the TeraGrid. To evaluate the current state of grid portal security, we undertake a comparative analysis of the three most popular grid portal frameworks that are being pursued as frontends to the TeraGrid: GridSphere, OGCE and clarens. We explore general challenges that grid portals face in the areas of authentication (including user identification), authorization, auditing (logging) and session management then contrast how the different grid portal implementations address these challenges. We find that although most grid portals address these security concerns to a certain extent, there is still room for improvement, particularly in the areas of secure default configurations and comprehensive logging and auditing support. We conclude with specific recommendations for designing, implementing and configuring secure grid portals