Policy management for networked systems and applications

被引:10
作者
Agrawal, D [1 ]
Calo, S [1 ]
Giles, J [1 ]
Lee, KW [1 ]
Verma, D [1 ]
机构
[1] IBM Corp, TJ Watson Res Ctr, Hawthorne, NY 10532 USA
来源
Integrated Network Management IX: MANAGING NEW NETWORKED WORLDS | 2005年
关键词
D O I
10.1109/INM.2005.1440816
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
In this paper, we present a novel policy middleware architecture for managing IT systems and applications that span multiple networks and administrative domains. The proposed policy middleware provides a standard infrastructure for the creation, storage, distribution, and execution of policies, and helps in reducing the cost of making IT systems policy-aware. In particular, we focus on three aspects of the proposed policy middleware that help in making the middleware fully general: (1) a platform-neutral and extensible specification of policies; (2) the local ratification of policies, which lets system administrators accept, reject, or flag an incoming policy; and (3) the transformation of policies, which allows system administrators to transform incoming policies to match their local environment. We present our experience in building an application on the proposed middleware to audit the configuration of a storage area network. We also present performance results from a prototype and show that our policy middleware design can scale to handle a large number of policies.
引用
收藏
页码:455 / 468
页数:14
相关论文
共 11 条
[1]  
AGRAWAL D, 2004, IEEE POLICY
[2]  
ALSHAER E, 2003, IEEE IM 2003
[3]  
BROWN A, 2001, XML SCHEMA FORMAL DE
[4]  
DAMIANOU N, 2001, IEEE POLICY 2001
[5]  
FLEGKAS P, 2003, IEEE IM 2003
[6]  
*IBM, 2004, AUT COMP CREAT SELF
[7]   A policy language for a pervasive computing environment [J].
Kagal, L ;
Finin, T ;
Joshi, A .
IEEE 4TH INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2003, :63-74
[8]  
MURUGANATHA HL, 2003, IEEE IM 2003
[9]  
*STOR NETW IND ASS, 2003, SNIA STOR MAN IN SPE
[10]   KAoS policy and domain services: Toward a description-logic approach to policy representation, deconfliction, and enforcement [J].
Uszok, A ;
Bradshaw, J ;
Jeffers, R ;
Suri, N ;
Hayes, P ;
Breedy, M ;
Bunch, L ;
Johnson, M ;
Kulkarni, S ;
Lott, J .
IEEE 4TH INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2003, :93-96