Скачиваний:
50
Добавлен:
20.06.2019
Размер:
50.48 Mб
Скачать

Chapter 18

Technologies for Enforcement and Distribution of Policy in Cloud Architectures

K.W. Scott Morrison

AbstractService-Oriented Architecture (SOA) has demonstrated the value of defining a decoupled policy layer for applications. This design pattern promotes a declarative-style approach to policy enforcement and offers a basis for reuse of rule sets. When an intermediary applies policy to a communication stream, it has utility beyond the simple application of authentication and authorization. In this role, policy is the language to articulate all actionable functions on a protocol stream, including (but not limited to) general cryptography, message transform, content validation, routing, orchestration, service level agreement enforcement, counters, audit, event management, and monitoring. Policy thus becomes the underpinning for the security and management of applications and data. This chapter is about the application of decoupled policy enforcement technology to cloud computing. It explores the use of the SOA Policy Enforcement Point (PEP) as a policy gateway in the cloud and shows this to be an effective security model for cloud services.

18.1  Introduction

Security of applications and data remains the primary concern among early adopters of cloud technology [3, 11, 24, 28]. This is not surprising, as the cloud community has struggled with articulating a comprehensive and cohesive security model. Early efforts from organizations such as the Cloud Security Alliance show promise [4], but cloud has fundamental challenges around trust that technology alone will not overcome. In this chapter, we demonstrate that a design pattern and associated technology that matured in the Service-Oriented Architecture (SOA) space, the intermediary SOA Policy Enforcement Point (PEP), can form the basis of an effective security model for applications and data residing in clouds.

K.W.S. Morrison (*)

Layer 7 Technologies, 1200 G Street, NW, Suite 800, Washington, DC 20005, USA e-mail: smorrison@layer7tech.com

N. Antonopoulos and L. Gillam (eds.), Cloud Computing: Principles,

305

Systems and Applications, Computer Communications and Networks,

DOI 10.1007/978-1-84996-241-4_18, © Springer-Verlag London Limited 2010

Соседние файлы в папке CLOUD COMPUTING