首页> 外文学位 >GABE: A cloud brokerage system for service selection, accountability and enforcement.
【24h】

GABE: A cloud brokerage system for service selection, accountability and enforcement.

机译:GABE:一种用于服务选择,问责制和执行的云经纪系统。

获取原文
获取原文并翻译 | 示例

摘要

Much like its meteorological counterpart, Cloud Computing is an amorphous agglomeration of entities. It is amorphous in that the exact layout of the servers, the load balancers and their functions are neither known nor fixed. Its an agglomerate in that multiple service providers and vendors often coordinate to form a multitenant system using virtualization. This complex environment offers great potential to providers and adopters, but also introduces great challenges in managing, combining and providing a variety of highly heterogeneous services. In particular, users interaction with these providers is often cumbersome, as the details of a cloud system are often abstracted away and unclear to most adopters. Further, cloud computing does not offer strong security guarantees, or traceability of data, and its indeterminate nature makes accountability of providers and users operations difficult. This nebulous nature and the lack of security assurances of Cloud services together form the foremost barriers to its adoption.;In this dissertation, we aim to address some of the most significant barriers to the adoption of Cloud services. We propose a novel brokerage-based architecture called GABE - a Cloud brokeraGe system for service selection, AccountaBility and, policy Enforcement. GABE fulfills two major needs of cloud users: helping them understand the Cloud services best suited for them; and providing security assurances on their data. As the core part of the brokerage system, we design a unique indexing technique for managing the information of a large number of Cloud service Providers. Multiple alternatives to the indexing are studied to address specific needs in service selection. We then develop efficient service selection algorithms that rank potential service providers and aggregate them if necessary.;GABE also helps users protect their data by providing a policy driven node selection methodology for map reduce architectures. GABE seamlessly integrates node selection control to the MapReduce framework for increased data security. It leverages data preprocessing techniques and distributed node verification protocols to achieve strong policy enforcement. We further augment GABE by equipping it with accountability features. In order to support accountability, we propose a novel highly decentralized information accountability framework to keep track of the actual usage of the users' data in the Cloud. In particular, we propose an object-centered approach that enables enclosing our logging mechanism together with users' data and policies. We leverage object oriented programming techniques to create a dynamic and traveling object, and to ensure that any access to users' data will trigger authentication and automated logging local to the JARs. We take a policy-driven approach that strongly couples data and content protection policies (CPPs). This approach constitutes an effective and practical solution for content protection for a number of reasons. First of all, both the CPPs and the protection mechanism travel with the content, which is stored in its original form. Secondly, users do not need to rely on any dedicated management system to specify and apply the CPPs. Thirdly, to strengthen users' control, we also provide distributed auditing mechanisms. We provide extensive experimental studies on real cloud computing testbeds that demonstrate the efficiency and effectiveness of the proposed policy driven node selection, auditing, and service selection approaches with real and synthetic Cloud data. (Abstract shortened by UMI.).
机译:就像它的气象对应物一样,云计算是实体的无定形聚集。这是不确定的,因为服务器,负载均衡器及其功能的确切布局既未知也不固定。它的聚集是因为多个服务提供商和供应商经常使用虚拟化来协调以形成多租户系统。这种复杂的环境为提供者和采用者提供了巨大的潜力,但是在管理,组合和提供各种高度异构的服务方面也带来了巨大的挑战。尤其是,用户与这些提供者的交互通常很麻烦,因为云系统的详细信息通常会被抽象化,并且大多数采用者不清楚。此外,云计算不能提供强大的安全性保证或数据的可追溯性,其不确定的性质使提供者和用户的操作难以承担责任。云服务的这种模糊性质和缺乏安全保证共同构成了对其采用的最大障碍。;本文旨在解决云服务采用中的一些最重要的障碍。我们提出了一种新颖的基于经纪的架构,称为GABE-一种用于服务选择,AccountaBility和策略执行的云经纪系统。 GABE满足了云用户的两个主要需求:帮助他们了解最适合他们的云服务;并为其数据提供安全保证。作为经纪系统的核心部分,我们设计了一种独特的索引技术来管理大量云服务提供商的信息。研究了索引的多种选择,以解决服务选择中的特定需求。然后,我们开发有效的服务选择算法,对潜在的服务提供商进行排名,并在必要时对其进行汇总。 GABE将节点选择控件无缝集成到MapReduce框架中,以提高数据安全性。它利用数据预处理技术和分布式节点验证协议来实现强大的策略实施。我们通过为GABE配备问责功能来进一步增强其功能。为了支持问责制,我们提出了一个新颖的高度分散的信息问责制框架,以跟踪云中用户数据的实际使用情况。特别是,我们提出了一种以对象为中心的方法,该方法可以将日志记录机制与用户的数据和策略一起封闭。我们利用面向对象的编程技术来创建动态和行进的对象,并确保对用户数据的任何访问都将触发JAR本地的身份验证和自动日志记录。我们采用政策驱动的方法,将数据和内容保护策略(CPP)紧密结合在一起。由于多种原因,这种方法构成了一种有效且实用的内容保护解决方案。首先,CPP和保护机制都随内容一起传播,内容以其原始形式存储。其次,用户不需要依靠任何专用的管理系统来指定和应用CPP。第三,为了加强用户的控制,我们还提供了分布式审核机制。我们在真实云计算测试平台上提供了广泛的实验研究,以证明所提出的策略驱动的节点选择,审计和服务选择方法对真实和合成Cloud数据的效率和有效性。 (摘要由UMI缩短。)。

著录项

  • 作者

    Sundareswaran, Smitha.;

  • 作者单位

    The Pennsylvania State University.;

  • 授予单位 The Pennsylvania State University.;
  • 学科 Information Technology.;Computer Science.
  • 学位 Ph.D.
  • 年度 2014
  • 页码 151 p.
  • 总页数 151
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号