The Experts below are selected from a list of 18 Experts worldwide ranked by ideXlab platform
Lisa Childers - One of the best experts on this subject based on the ideXlab platform.
-
the Security Descriptor
Globus® Toolkit 4#R##N#Programming Java Services, 2006Co-Authors: Borja Sotomayor, Lisa ChildersAbstract:The Security Descriptor file can be used to configure client-side Security or to specify the Security options of the standalone container. It can even be used to specify Security options at the resource level using a Security Descriptor. This chapter takes a look at what can be done with the Security Descriptor. The four types of Descriptors have a set of common options. First of all, the resource Descriptor can be used to specify what credentials must be used during a secure communication. It can be specified what authentication method and what authorization method must be used at the resource level. Instead of configuring client-side Security programmatically, it can also be done using a client Security Descriptor. This Descriptor specifies the global Security options that affect the whole container. The location of the Descriptor is specified in the container's WSDD file. Two options allow one to control certain aspects of message-level Security. The first option affects GSI Secure Conversation. The second option affects GSI Secure Message that is potentially vulnerable to a type of attack called replay attack.
-
chapter 20 – Authorization
Globus® Toolkit 4, 2006Co-Authors: Borja Sotomayor, Lisa ChildersAbstract:Publisher Summary This chapter reviews each of the authorization mechanisms included in GSI and explains what changes must be made in the services to use them. It starts by taking a brief look at what code must be added to a service's or resource's Security Descriptor to use server-side authorization, and what each type of authorization is commonly used for. Next, the chapter takes a much closer look at one particular type of server-side authorization, gridmap authorization, by working through an example service that uses gridmaps. Then, it takes a look at the different types of client-side authorization. Finally, the chapter briefly discusses how GT4 allows it to implement custom authorization mechanisms. Gridmaps are one of the best-known forms of server-side authorization, playing an important role in higher-level services. A gridmap is basically an ACL (Access Control List) that allows one to specify what users have access to a service. The authorization mechanisms included with the toolkit will allow dealing with simple authorization scenarios. For more complex authorization scenarios, GT4 provides an infrastructure to easily implement custom authorization mechanisms to use in services.
-
Run-as Modes and Delegation
Globus® Toolkit 4, 2006Co-Authors: Borja Sotomayor, Lisa ChildersAbstract:The two final examples of this chapter show how an adequate combination of authentication, authorization, and credential delegation can make services pretty secure. The chapter starts with a brief explanation of run-as modes, another parameter that can be configured in the Security Descriptor and that makes the most sense in the context of credential delegation. Then, a trivial example of delegation is seen, followed by a more elaborate (and non-trivial) example of credential delegation. Next, one will see how one can delegate credentials to a specific resource. Finally, the chapter briefly discusses about the GT4 Delegation Service. The run-as modes allows control over the credentials the service uses during the course of an invocation. The chapter starts working on a more elaborate delegation example which uses two services: PhysicsService, and MathService. Next, it shows an example of an interesting, and useful, Security scenario that is solved with delegation. All through this chapter it is seen how to delegate credentials programmatically. However, it is also possible to do this at a higher level, by using a Web services interface. GT4 supplies a delegation service that allows delegating credentials to any service that is deployed in the same container as the delegation service. This service also provides an interface to easily refresh the delegated credentials.
Borja Sotomayor - One of the best experts on this subject based on the ideXlab platform.
-
the Security Descriptor
Globus® Toolkit 4#R##N#Programming Java Services, 2006Co-Authors: Borja Sotomayor, Lisa ChildersAbstract:The Security Descriptor file can be used to configure client-side Security or to specify the Security options of the standalone container. It can even be used to specify Security options at the resource level using a Security Descriptor. This chapter takes a look at what can be done with the Security Descriptor. The four types of Descriptors have a set of common options. First of all, the resource Descriptor can be used to specify what credentials must be used during a secure communication. It can be specified what authentication method and what authorization method must be used at the resource level. Instead of configuring client-side Security programmatically, it can also be done using a client Security Descriptor. This Descriptor specifies the global Security options that affect the whole container. The location of the Descriptor is specified in the container's WSDD file. Two options allow one to control certain aspects of message-level Security. The first option affects GSI Secure Conversation. The second option affects GSI Secure Message that is potentially vulnerable to a type of attack called replay attack.
-
chapter 20 – Authorization
Globus® Toolkit 4, 2006Co-Authors: Borja Sotomayor, Lisa ChildersAbstract:Publisher Summary This chapter reviews each of the authorization mechanisms included in GSI and explains what changes must be made in the services to use them. It starts by taking a brief look at what code must be added to a service's or resource's Security Descriptor to use server-side authorization, and what each type of authorization is commonly used for. Next, the chapter takes a much closer look at one particular type of server-side authorization, gridmap authorization, by working through an example service that uses gridmaps. Then, it takes a look at the different types of client-side authorization. Finally, the chapter briefly discusses how GT4 allows it to implement custom authorization mechanisms. Gridmaps are one of the best-known forms of server-side authorization, playing an important role in higher-level services. A gridmap is basically an ACL (Access Control List) that allows one to specify what users have access to a service. The authorization mechanisms included with the toolkit will allow dealing with simple authorization scenarios. For more complex authorization scenarios, GT4 provides an infrastructure to easily implement custom authorization mechanisms to use in services.
-
Run-as Modes and Delegation
Globus® Toolkit 4, 2006Co-Authors: Borja Sotomayor, Lisa ChildersAbstract:The two final examples of this chapter show how an adequate combination of authentication, authorization, and credential delegation can make services pretty secure. The chapter starts with a brief explanation of run-as modes, another parameter that can be configured in the Security Descriptor and that makes the most sense in the context of credential delegation. Then, a trivial example of delegation is seen, followed by a more elaborate (and non-trivial) example of credential delegation. Next, one will see how one can delegate credentials to a specific resource. Finally, the chapter briefly discusses about the GT4 Delegation Service. The run-as modes allows control over the credentials the service uses during the course of an invocation. The chapter starts working on a more elaborate delegation example which uses two services: PhysicsService, and MathService. Next, it shows an example of an interesting, and useful, Security scenario that is solved with delegation. All through this chapter it is seen how to delegate credentials programmatically. However, it is also possible to do this at a higher level, by using a Web services interface. GT4 supplies a delegation service that allows delegating credentials to any service that is deployed in the same container as the delegation service. This service also provides an interface to easily refresh the delegated credentials.
Andrey Molyakov - One of the best experts on this subject based on the ideXlab platform.
-
New Security Descriptor computing algorithm of Supercomputers
2019 Third World Conference on Smart Trends in Systems Security and Sustainablity (WorldS4), 2019Co-Authors: Andrey MolyakovAbstract:The author describes computing algorithm based on new scientific definition - “The resulting convolution, which takes into account changes in the significant bits of variables of the Zhegalkin polynomial, is a superposition of hash function calculations for the i-th process”.
Timothy Mullen - One of the best experts on this subject based on the ideXlab platform.
-
Remote Security Log Collection in a Least Privilege Environment
Thor's Microsoft Security Bible, 2011Co-Authors: Timothy MullenAbstract:This chapter focuses on using a low privileged service user to harvest Windows event log data and to warehouse it in a SQL database. This is done with the minimum of permissions over an encrypted Distributed Component Object Model (DCOM) call via Windows Management Instrumentation (WMI), using Security Descriptor Definition Language (SDDL) for individual event log permissions. It includes a fully functional code example.
Guido Grillenmeier - One of the best experts on this subject based on the ideXlab platform.
-
Windows Server 2003 Authorization
Microsoft Windows Security Fundamentals, 2007Co-Authors: Jan De Clercq, Guido GrillenmeierAbstract:Publisher Summary This chapter focuses on the authorization service that protects against unauthorized use and explains the interaction between an entity and a resource. The discussion begins with authorization basics and later on explains the Windows authorization model. Authorization always deals with two entities: a subject and an object, which the subject wants to access. In Active Directory, a subject can be a Security principal such as a user. The object can be file resources hosted on a file server, eMails on a mailbox server.. Authorization between the subject and the object is typically executed and enforced by a third entity that is generally referred to as the reference monitor. In a Windows environment, this third entity is known as the Security Reference Monitor (SRM). The SRM runs in the highly privileged OS kernel mode and checks all access to resources as requested by code that is running in user mode. To ease access control management in large distributed computing environment, Windows include authorization intermediaries, that is, groups and user rights. Groups provide a way to group entities with similar capabilities, whereas, user rights define the capabilities of subjects to manage system resources and to perform system-related tasks. The Chapter also provides an overview of the Windows 2000 authorization changes and Windows 2003 authorization changes. The former one includes the new ACL editor, ACL inheritance, controlling inheritance, object type-based ACEs, and ACL evaluation process. The changes in the latter one are increased restrictive authorization settings, effective permissions, default AD Security Descriptor changes, AD link value replication and group membership updates, quota for AD objects, hiding data in the file systems and shares, and the confidential bit for AD attributes. The chapter concludes with the discussion on authorization manager, Windows Server 2003 RBAC architecture and its major components, and list of authorization tools.