Building a demilitarized zone with data encryption for grid environments

  • Authors:
  • Matthias Schmidt;Matthew Smith;Niels Fallenbeck;Hans Picht;Bernd Freisleben

  • Affiliations:
  • University of Marburg, Marburg, Germany;University of Marburg, Marburg, Germany;University of Marburg, Marburg, Germany;University of Marburg, Marburg, Germany;University of Marburg, Marburg, Germany

  • Venue:
  • Proceedings of the first international conference on Networks for grid applications
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security and data integrity are important aspects in the fields of Grid and cluster computing. When these two areas are combined, the security issues intermingle and new security concepts are needed to ensure protection of both Grid users and local cluster users. In this paper, a novel dual laned Demilitarized Zone (DMZ) to protect local clusters from Grid attacks is introduced. The Globus Security Infrastructure (GSI) is extended to enable safe end-to-end encryption of Grid jobs through the DMZ and into virtualized execution hosts. Finally, an integrated Network Intrusion Detection System with Grid-specific rules, further protecting the Grid DMZ, is presented.