Next-generation big data federation access control: A reference model

This paper discusses one of the most significant challenges of next-generation big data (BD) federation platforms, namely, Hadoop access control. Privacy and security on a federation scale remain significant concerns among practitioners in both industry and academia. Hadoop’s current primitive acces...

Descripción completa

Detalles Bibliográficos
Autores: Awaysheh, Feras M., Alazab, Mamoun, Gupta, Maanak, Fernández Pena, Anselmo Tomás, Cabaleiro Domínguez, José Carlos
Tipo de recurso: artículo
Fecha de publicación:2020
País:España
Institución:Universidad de Santiago de Compostela (USC)
Repositorio:Minerva. Repositorio Institucional de la Universidad de Santiago de Compostela
Idioma:inglés
OAI Identifier:oai:minerva.usc.gal:10347/42116
Acceso en línea:https://hdl.handle.net/10347/42116
Access Level:acceso abierto
Palabra clave:Big Data
Hadoop 3.x
Identification and access management
HDFS federation
Reference model
Security broker
Access logs analysis
id ES_a129fd6e3abc6c61899d54bbf320c11a
oai_identifier_str oai:minerva.usc.gal:10347/42116
network_acronym_str ES
network_name_str España
repository_id_str
spelling Next-generation big data federation access control: A reference modelAwaysheh, Feras M.Alazab, MamounGupta, MaanakFernández Pena, Anselmo TomásCabaleiro Domínguez, José CarlosBig DataHadoop 3.xIdentification and access managementHDFS federationReference modelSecurity brokerAccess logs analysisThis paper discusses one of the most significant challenges of next-generation big data (BD) federation platforms, namely, Hadoop access control. Privacy and security on a federation scale remain significant concerns among practitioners in both industry and academia. Hadoop’s current primitive access control presents security concerns and limitations, such as the complexity of deployment and the consumption of resources. However, this major concern has not been a subject of intensive study in the literature. This paper critically reviews and investigates these security limitations and provides a framework called BD federation access broker to address 8 main security limitations. This paper proposes the federated access control reference model (FACRM) to formalize the design of secure BD solutions within the Apache Hadoop stack. Furthermore, this paper discusses the implementation of the access broker and its usefulness for security breach detection and digital forensics investigations. The efficiency of the proposed access broker has not sustainably affected the performance overhead. The experimental results show only 1% of each 100 MB read/write operation in a WebHDFS. Overall, the findings of the paper pave the way for a wide range of revolutionary and state-of-the-art enhancements and future trends within Hadoop stack security and privacy.ElsevierUniversidade de Santiago de Compostela. Centro de Investigación en Tecnoloxías Intelixentes da USC (CiTIUS)20202020-03-1320202020-03-13journal articlehttp://purl.org/coar/resource_type/c_6501AMhttp://purl.org/coar/version/c_ab4af688f83e57aainfo:eu-repo/semantics/articleapplication/pdfhttps://hdl.handle.net/10347/42116reponame:Minerva. Repositorio Institucional de la Universidad de Santiago de Compostelainstname:Universidad de Santiago de Compostela (USC)Inglésengopen accesshttp://purl.org/coar/access_right/c_abf2Attribution-NonCommercial-NoDerivatives 4.0 Internationalhttp://creativecommons.org/licenses/by-nc-nd/4.0/info:eu-repo/semantics/openAccessoai:minerva.usc.gal:10347/421162026-06-15T12:47:27Z
dc.title.none.fl_str_mv Next-generation big data federation access control: A reference model
title Next-generation big data federation access control: A reference model
spellingShingle Next-generation big data federation access control: A reference model
Awaysheh, Feras M.
Big Data
Hadoop 3.x
Identification and access management
HDFS federation
Reference model
Security broker
Access logs analysis
title_short Next-generation big data federation access control: A reference model
title_full Next-generation big data federation access control: A reference model
title_fullStr Next-generation big data federation access control: A reference model
title_full_unstemmed Next-generation big data federation access control: A reference model
title_sort Next-generation big data federation access control: A reference model
dc.creator.none.fl_str_mv Awaysheh, Feras M.
Alazab, Mamoun
Gupta, Maanak
Fernández Pena, Anselmo Tomás
Cabaleiro Domínguez, José Carlos
author Awaysheh, Feras M.
author_facet Awaysheh, Feras M.
Alazab, Mamoun
Gupta, Maanak
Fernández Pena, Anselmo Tomás
Cabaleiro Domínguez, José Carlos
author_role author
author2 Alazab, Mamoun
Gupta, Maanak
Fernández Pena, Anselmo Tomás
Cabaleiro Domínguez, José Carlos
author2_role author
author
author
author
dc.contributor.none.fl_str_mv Universidade de Santiago de Compostela. Centro de Investigación en Tecnoloxías Intelixentes da USC (CiTIUS)

dc.subject.none.fl_str_mv Big Data
Hadoop 3.x
Identification and access management
HDFS federation
Reference model
Security broker
Access logs analysis
topic Big Data
Hadoop 3.x
Identification and access management
HDFS federation
Reference model
Security broker
Access logs analysis
description This paper discusses one of the most significant challenges of next-generation big data (BD) federation platforms, namely, Hadoop access control. Privacy and security on a federation scale remain significant concerns among practitioners in both industry and academia. Hadoop’s current primitive access control presents security concerns and limitations, such as the complexity of deployment and the consumption of resources. However, this major concern has not been a subject of intensive study in the literature. This paper critically reviews and investigates these security limitations and provides a framework called BD federation access broker to address 8 main security limitations. This paper proposes the federated access control reference model (FACRM) to formalize the design of secure BD solutions within the Apache Hadoop stack. Furthermore, this paper discusses the implementation of the access broker and its usefulness for security breach detection and digital forensics investigations. The efficiency of the proposed access broker has not sustainably affected the performance overhead. The experimental results show only 1% of each 100 MB read/write operation in a WebHDFS. Overall, the findings of the paper pave the way for a wide range of revolutionary and state-of-the-art enhancements and future trends within Hadoop stack security and privacy.
publishDate 2020
dc.date.none.fl_str_mv 2020
2020-03-13
2020
2020-03-13
dc.type.none.fl_str_mv journal article
http://purl.org/coar/resource_type/c_6501
AM
http://purl.org/coar/version/c_ab4af688f83e57aa
dc.type.openaire.fl_str_mv info:eu-repo/semantics/article
format article
dc.identifier.none.fl_str_mv https://hdl.handle.net/10347/42116
url https://hdl.handle.net/10347/42116
dc.language.none.fl_str_mv Inglés
eng
language_invalid_str_mv Inglés
language eng
dc.rights.none.fl_str_mv open access
http://purl.org/coar/access_right/c_abf2
Attribution-NonCommercial-NoDerivatives 4.0 International
http://creativecommons.org/licenses/by-nc-nd/4.0/
dc.rights.openaire.fl_str_mv info:eu-repo/semantics/openAccess
rights_invalid_str_mv open access
http://purl.org/coar/access_right/c_abf2
Attribution-NonCommercial-NoDerivatives 4.0 International
http://creativecommons.org/licenses/by-nc-nd/4.0/
eu_rights_str_mv openAccess
dc.format.none.fl_str_mv application/pdf
dc.publisher.none.fl_str_mv Elsevier
publisher.none.fl_str_mv Elsevier
dc.source.none.fl_str_mv reponame:Minerva. Repositorio Institucional de la Universidad de Santiago de Compostela
instname:Universidad de Santiago de Compostela (USC)
instname_str Universidad de Santiago de Compostela (USC)
reponame_str Minerva. Repositorio Institucional de la Universidad de Santiago de Compostela
collection Minerva. Repositorio Institucional de la Universidad de Santiago de Compostela
repository.name.fl_str_mv
repository.mail.fl_str_mv
_version_ 1869415105119125504
score 15,812429