DynamicFirewallsandServiceDeploymentModelsforGrid网格的动态防火墙和服务的部署模型

上传人:e****s 文档编号:252475097 上传时间:2024-11-16 格式:PPT 页数:16 大小:976KB
返回 下载 相关 举报
DynamicFirewallsandServiceDeploymentModelsforGrid网格的动态防火墙和服务的部署模型_第1页
第1页 / 共16页
DynamicFirewallsandServiceDeploymentModelsforGrid网格的动态防火墙和服务的部署模型_第2页
第2页 / 共16页
DynamicFirewallsandServiceDeploymentModelsforGrid网格的动态防火墙和服务的部署模型_第3页
第3页 / 共16页
点击查看更多>>
资源描述
Click to edit Master title style,Click to edit Master text styles,Second level,Third level,Fourth level,Fifth level,anne itti,|16-10-2006|Slide,Regional Computing Centre for Lower Saxony,Dynamic Firewalls and Service Deployment Models for Grid Environments,Gian Luca Volpato,Christian Grimm,RRZN Leibniz Universitt Hannover,Cracow Grid Workshop 2006(CGW2006),15,th,-18,th,October 2006,Overview,Dynamic Firewall,General concepts,Dyna-Fire,Cooperative On-Demand Opening(CODO),Limitations,Globus Toolkit deployment model,Services at the Resource Provider,Use of existing computing infrastructure,Minimal number of connections through the site firewall,A Firewall is a piece of hardware and/or software which functions in a network environment to prevent some communications forbidden by the security policy.*,Good,:it blocks unwanted and malicious traffic.,Bad,:it might be not flexible enough to allow seamless execution of Grid applications.,*Wikipedia,Firewall,Dynamic Firewall,Goal,Protect a network so that it appears completely inaccessible from external systems but still responds to trusted clients,i.e.allow external connections on-demand.,Current solutions,Signaling protocol to add/remove filtering rules:,“Off-path:communication between applications and firewalls,“In-path:communication between application peers intercepted by intermediate firewalls,Dyna-Fire&Cooperative On-Demand Opening,One,daemon,runs on the same host of the firewall to:,monitor all connection requests,add/remove filtering rules in the firewall,A connection is allowed when the client request is successfully authenticated and authorized.,Signaling protocol:,Dyna,-Fire,=,messages carried by,Port Knocking,CODO =messages carried over,SSL channel,1,2,Intranet,Library,Client Application,Server Application,Daemon,Limitations of dynamic firewalls,No mechanism to discover automatically the firewalls along the path,Signaling before connection establishment?,Static routing table configuration,Dyna-Fire and Port Knocking,CPU overhead for monitoring of connection attempts,Exclusive reservation of some ports,Unidirectional protocol exposed to reply and man-in-the-middle attacks,CODO,Applications(client and server!)must be recompiled/relinked with a special socket library,Authorization policy is coarse-grained and not flexible,Deployment model for Globus Toolkit 4,DMZ,Local,MDS-Index,GridFTP Server,RFT,Server,GRAM Server,User Interface,Batch System Nodes,Intranet,Batch System,Master,Constraints,Use existing batch computing resources,GT4 services must be reachable from the Internet,Goals,Avoid any connection between:,hosts in the,Intranet,and hosts in the,external Internet,Identify,analyze and reduce the connections between:,hosts in the,Intranet,and GT services in the,DMZ,Batch system,Batch System Nodes,Intranet,Batch System,Master,DMZ,GRAM Server,Batch Sys.Login Node,Install Globus GRAM on a host that can submit jobs to the Batch System,Either:,Enable shared file system between this node and the Batch System,Modify GRAM scripts in order to use Batch System functions for file stage-in and file stage-out,GridFTP option 1,Batch System Nodes,Intranet,Batch System,Master,DMZ,GridFTP Server,GridFTP server and Batch System have a shared file system,Input files are transferred to the local GridFTP server before jobs are submitted to the local GRAM server,Output files are stored in the local GridFTP server,GridFTP option 2,Batch System Nodes,Intranet,DMZ,GridFTP Server,Batch System,Master,System nodes have direct access to the local GridFTP server,Input files are transferred to the local GridFTP server before jobs are submitted to the local GRAM server,Output files are uploaded to the local GridFTP server,Reliable File Transfer,DMZ,Batch System Nodes,Intranet,Batch System,Master,GRAM Server,Batch Sys.Login Node,RFT,Server,GridFTP Server,RFT server is installed on the same host where the GRAM server runs,Connections are established:,within the DMZ,between the DMZ and the external Internet,MDS,Batch System Nodes,Intranet,Batch System,Master,DMZ,GRAM Server,Batch Sys.Login Node,RFT,Server,GridFTP Server,Local,MDS-Index,Deploy one MDS-Index that collects monitoring information from all local GRAM and RFT servers(in future also GridFTP servers),Connections are established:,within the DMZ,between the DMZ and the external Internet,Batch System Master and GRAM server(Ganglia,Nagios,etc.),User Interface,Batch System Nodes,Intranet,Batch System,Master,DMZ,GRAM Server,Batch Sys.Login Node,RFT,Server,GridFTP Server,Local,MDS-Index,User Interface,The User Interface is used to submit/monitor/manage Grid jobs,Connections are established:,within the DMZ,between the DMZ and the external Internet,Full model,User Interface,Batch System Nodes,Intranet,Batch System,Master,DMZ,GRAM Server,Batch Sys.Login Node,RFT,Server,GridFTP Server,Local,MDS-Index,GRAM,RFT,Batch System,User Interface,MDS,GridFTP,Shared File System,Summary,Dynamic Firewall,General concepts,Dyna-Fire,Cooperative on Demand Ope
展开阅读全文
相关资源
正为您匹配相似的精品文档
相关搜索

最新文档


当前位置:首页 > 商业管理 > 商业计划


copyright@ 2023-2025  zhuangpeitu.com 装配图网版权所有   联系电话:18123376007

备案号:ICP2024067431-1 川公网安备51140202000466号


本站为文档C2C交易模式,即用户上传的文档直接被用户下载,本站只是中间服务平台,本站所有文档下载所得的收益归上传人(含作者)所有。装配图网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。若文档所含内容侵犯了您的版权或隐私,请立即通知装配图网,我们立即给予删除!