Title :
Tools for domain-based policy management of distributed systems
Author :
Damianou, N. ; Dulay, N. ; Lupu, E. ; Sloman, M. ; Tonouchi, T.
Author_Institution :
Dept. of Comput., Imperial Coll. of Sci., Technol. & Med., London, UK
Abstract :
The management of policies in large-scale systems is complex because of the potentially large number of policies and administrators, as well as the diverse types of information that need to be managed. Appropriate tool support is essential to make management practical and feasible. In this paper we present the implementation of an integrated toolkit for the specification, deployment and management of policies specified in the PONDER language. PONDER policies provide a powerful framework for managing distributed systems which includes explicit domain-based subject and target specifications as well as a flexible life-cycle and deployment model. Domains, implemented using LDAP directories, are used for storing policies and grouping resources, people, and the entities which implement policy, thus facilitating the automated dissemination of policy information. The toolkit presented in this paper comprises: a policy compiler, used to generate implementation code for heterogeneous management and security platforms, a hyperbolic tree viewer for efficient manipulation of the domain structure and effective navigation across the domains, and various tools for deploying and managing the policy life-cycle.
Keywords :
computer network management; distributed object management; information dissemination; large-scale systems; program compilers; security of data; specification languages; telecommunication security; tree data structures; LDAP directories; PONDER language; automated dissemination; deployment model; distributed systems management; domain structure manipulation; domain-based policy management; flexible life-cycle model; heterogeneous management platforms; hyperbolic tree viewer; implementation code generation; integrated toolkit; large-scale systems; navigation; policy compiler; policy information; policy specification language; security platforms; subject specifications; target specifications; Computer network management; Computer networks; Distributed computing; Educational institutions; Humans; Information management; Laboratories; Power system management; Resource management; Scalability;
Conference_Titel :
Network Operations and Management Symposium, 2002. NOMS 2002. 2002 IEEE/IFIP
Print_ISBN :
0-7803-7382-0
DOI :
10.1109/NOMS.2002.1015565