• DocumentCode
    679022
  • Title

    OnTimeSecure: Secure middleware for federated Network Performance Monitoring

  • Author

    Calyam, Prasad ; Kulkarni, Santosh ; Berryman, Alex ; Kunpeng Zhu ; Sridharan, M. ; Ramnath, Rajiv ; Springer, Gordon

  • Author_Institution
    Univ. of Missouri-Columbia, Columbia, MO, USA
  • fYear
    2013
  • fDate
    14-18 Oct. 2013
  • Firstpage
    100
  • Lastpage
    104
  • Abstract
    Multi-domain network monitoring systems based on active measurements are being widely deployed in high-performance computing and other communities that support large-scale data transfers. Security mechanisms such as policy-driven access to related federated Network Performance Monitoring (NPM) services are important to protect measurement resources and data. In this paper, we present a novel, secure middleware framework viz., “OnTimeSecure” that enables `user-to-service´ and `service-to-service´ authentication, and enforces federated authorization entitlement policies for timely orchestration of NPM services. OnTimeSecure is built using RESTful APIs and features a hierarchical policy-engine that interfaces with a meta-scheduler for prioritization of measurement requests when there is contention of users concurrently attempting to utilize measurement resources. We validate OnTimeSecure in a federated multi-domain NPM infrastructure by performing threat modeling and security risk assessments based on overall attack likelihood and impact factors.
  • Keywords
    computer network performance evaluation; computer network security; middleware; monitoring; NPM services; OnTimeSecure; RESTful API; attack likelihood; federated authorization entitlement policies; federated multidomain NPM infrastructure; federated network performance monitoring services; hierarchical policy engine; high performance computing; large scale data transfers; measurement resources; metascheduler; multidomain network monitoring systems; policy driven access; secure middleware framework; security mechanisms; security risk assessments; service-to-service authentication; threat modeling; user-to-service authentication; Authentication; Authorization; Conferences; Current measurement; Loss measurement; Monitoring; enterprise access policy; entitlement service; federated identity; multi-domain measurements; secure middleware;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and Service Management (CNSM), 2013 9th International Conference on
  • Conference_Location
    Zurich
  • Type

    conf

  • DOI
    10.1109/CNSM.2013.6727815
  • Filename
    6727815