Title :
OnTimeSecure: Secure middleware for federated Network Performance Monitoring
Author :
Calyam, Prasad ; Kulkarni, Santosh ; Berryman, Alex ; Kunpeng Zhu ; Sridharan, M. ; Ramnath, Rajiv ; Springer, Gordon
Author_Institution :
Univ. of Missouri-Columbia, Columbia, MO, USA
Abstract :
Multi-domain network monitoring systems based on active measurements are being widely deployed in high-performance computing and other communities that support large-scale data transfers. Security mechanisms such as policy-driven access to related federated Network Performance Monitoring (NPM) services are important to protect measurement resources and data. In this paper, we present a novel, secure middleware framework viz., “OnTimeSecure” that enables `user-to-service´ and `service-to-service´ authentication, and enforces federated authorization entitlement policies for timely orchestration of NPM services. OnTimeSecure is built using RESTful APIs and features a hierarchical policy-engine that interfaces with a meta-scheduler for prioritization of measurement requests when there is contention of users concurrently attempting to utilize measurement resources. We validate OnTimeSecure in a federated multi-domain NPM infrastructure by performing threat modeling and security risk assessments based on overall attack likelihood and impact factors.
Keywords :
computer network performance evaluation; computer network security; middleware; monitoring; NPM services; OnTimeSecure; RESTful API; attack likelihood; federated authorization entitlement policies; federated multidomain NPM infrastructure; federated network performance monitoring services; hierarchical policy engine; high performance computing; large scale data transfers; measurement resources; metascheduler; multidomain network monitoring systems; policy driven access; secure middleware framework; security mechanisms; security risk assessments; service-to-service authentication; threat modeling; user-to-service authentication; Authentication; Authorization; Conferences; Current measurement; Loss measurement; Monitoring; enterprise access policy; entitlement service; federated identity; multi-domain measurements; secure middleware;
Conference_Titel :
Network and Service Management (CNSM), 2013 9th International Conference on
Conference_Location :
Zurich
DOI :
10.1109/CNSM.2013.6727815