Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP

HP.com home


Technical Reports



» 

HP Labs

» Research
» News and events
» Technical reports
» About HP Labs
» Careers @ HP Labs
» People
» Worldwide sites
» Downloads
Content starts here

 

Managing ACLs in a distributed system

Bhatt, Sandeep; Horne, Bill; Rajagopalan, S.; Rao, Prasad

HPL-2007-171

Keyword(s): access control, validation, configuration generation, e nd-to-end requirements

Abstract: Managing access control in a distributed system is a challenge. Components across the technology stack - network devices, infrastructure servers, and software applications - contain access control lists. Managing these ACLs requires skilled administrators, often from different organizations and at different sites. Moreover, the ACLs must be coordinated to satisfy the high-level, end-to-end access requirements of the enterprise. Current procedures to coordinate ACLs are manual; not only is this slow and costly, but it is prone to sub tle errors. A significant problem stems from the fact that there can be multiple ways to access a resource; some of these paths are indirect, transiting through multiple component applications, making them hard to find. When access to a resource must be blocked, every path - direct and indirect - must be blocked. The inability to determine all access paths is one cause of poorly configured and vul nerable systems. This report presents a systematic approach to manage ACLs in a distributed system. We describe our prototype system, Vantage, and illustrate its use in managing 3-tier web architectures to comply with end- to-end access requirements. Our approach is based on models that capture the input-output behavior of individual components; the models are designed to allow efficient and scalable algorithms to analyze systems and to generate component ACLs that are compliant with end-to-end access requirements

16 Pages

Back to Index

»Technical Reports

» 2009
» 2008
» 2007
» 2006
» 2005
» 2004
» 2003
» 2002
» 2001
» 2000
» 1990 - 1999

Heritage Technical Reports

» Compaq & DEC Technical Reports
» Tandem Technical Reports
Printable version
Privacy statement Using this site means you accept its terms Feedback to HP Labs
© 2009 Hewlett-Packard Development Company, L.P.