Guardat: enforcing data policies at the storage layer

Guardat: enforcing data policies at the storage layer
复制标题

Guardat:在存储层执行数据策略

DOI:
--
复制
发表时间:
2015
期刊:
European Conference on Computer Systems
影响因子:
--
通讯作者:
Ansley Post
Ansley Post
中科院分区:
--
文献类型:
--
作者:
Anjo Vahldiek;Eslam Elnikety;Aastha Mehta;D. Garg;P. Druschel;R. Rodrigues;J. Gehrke;Ansley Post

文献摘要

被引文献

相似文献

在当今的数据处理系统中,保护存储数据的策略及其执行机制都分布在许多软件组件和配置文件中,这增加了由于错误、漏洞和错误配置而违反策略的风险。Guardat解决了这个问题。用户、开发人员和管理员以声明、简洁和独立于代码的方式指定文件保护策略,而Guardat通过在存储层协调I/O来执行这些策略。策略实施仅依赖于Guardat控制器和任何外部策略依赖项的完整性。使用Guardat的加密证明弥合了存储层实施和按文件策略之间的语义鸿沟。我们给出了Guardat的设计和原型实现,并在Web服务器上实施了示例策略,实验表明它的开销很低。
In today's data processing systems, both the policies protecting stored data and the mechanisms for their enforcement are spread over many software components and configuration files, increasing the risk of policy violation due to bugs, vulnerabilities and misconfigurations. Guardat addresses this problem. Users, developers and administrators specify file protection policies declaratively, concisely and separate from code, and Guardat enforces these policies by mediating I/O in the storage layer. Policy enforcement relies only on the integrity of the Guardat controller and any external policy dependencies. The semantic gap between the storage layer enforcement and per-file policies is bridged using cryptographic attestations from Guardat. We present the design and prototype implementation of Guardat, enforce example policies in a Web server, and show experimentally that its overhead is low.