DocumentCode
679022
Title
OnTimeSecure: Secure middleware for federated Network Performance Monitoring
Author
Calyam, Prasad ; Kulkarni, Santosh ; Berryman, Alex ; Kunpeng Zhu ; Sridharan, M. ; Ramnath, Rajiv ; Springer, Gordon
Author_Institution
Univ. of Missouri-Columbia, Columbia, MO, USA
fYear
2013
fDate
14-18 Oct. 2013
Firstpage
100
Lastpage
104
Abstract
Multi-domain network monitoring systems based on active measurements are being widely deployed in high-performance computing and other communities that support large-scale data transfers. Security mechanisms such as policy-driven access to related federated Network Performance Monitoring (NPM) services are important to protect measurement resources and data. In this paper, we present a novel, secure middleware framework viz., “OnTimeSecure” that enables `user-to-service´ and `service-to-service´ authentication, and enforces federated authorization entitlement policies for timely orchestration of NPM services. OnTimeSecure is built using RESTful APIs and features a hierarchical policy-engine that interfaces with a meta-scheduler for prioritization of measurement requests when there is contention of users concurrently attempting to utilize measurement resources. We validate OnTimeSecure in a federated multi-domain NPM infrastructure by performing threat modeling and security risk assessments based on overall attack likelihood and impact factors.
Keywords
computer network performance evaluation; computer network security; middleware; monitoring; NPM services; OnTimeSecure; RESTful API; attack likelihood; federated authorization entitlement policies; federated multidomain NPM infrastructure; federated network performance monitoring services; hierarchical policy engine; high performance computing; large scale data transfers; measurement resources; metascheduler; multidomain network monitoring systems; policy driven access; secure middleware framework; security mechanisms; security risk assessments; service-to-service authentication; threat modeling; user-to-service authentication; Authentication; Authorization; Conferences; Current measurement; Loss measurement; Monitoring; enterprise access policy; entitlement service; federated identity; multi-domain measurements; secure middleware;
fLanguage
English
Publisher
ieee
Conference_Titel
Network and Service Management (CNSM), 2013 9th International Conference on
Conference_Location
Zurich
Type
conf
DOI
10.1109/CNSM.2013.6727815
Filename
6727815
Link To Document