作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2018, Vol. 44 ›› Issue (12): 94-101. doi: 10.19678/j.issn.1000-3428.0049104

• 体系结构与软件技术 • 上一篇    下一篇

Hadoop平台的安全加固方案

丁祥武,张东辉   

  1. 东华大学 计算机科学与技术学院,上海 201620
  • 收稿日期:2017-10-27 出版日期:2018-12-15 发布日期:2018-12-15
  • 作者简介:丁祥武(1963—),男,副教授,主研方向为Hadoop分布式架构、系统安全、大数据、分布式计算;张东辉,硕士研究生
  • 基金资助:

    上海市信息化发展专项资金项目(XX-XXFZ-05-16-0139);上海市科技行动计划项目(15511106900)

Safety Reinforcement Scheme for Hadoop Platform

DING Xiangwu,ZHANG Donghui   

  1. School of Computer Science and Technology,Donghua University,Shanghai 201620,China
  • Received:2017-10-27 Online:2018-12-15 Published:2018-12-15

摘要:

针对Hadoop平台安全漏洞问题,通过分析Hadoop平台的安全现状,提出尚存的安全隐患,并对此安全隐患设计实现相关的加固方案。通过集成Hadoop认证系统与高可用的企业身份管理系统,实现由企业安全系统统一管理用户及权限信息,从而有效提高认证效率。同时启用字段级访问控制策略,提升用户对数据管理的灵活性。建立基于集群资源的健康评价体系,对集群的健康状态进行把控,为整个Hadoop集群的安全运行提供保障。实验结果验证了该方案的可行性与有效性。

关键词: Hadoop平台, 企业安全系统, 高可用性, 字段级访问控制, 健康评价体系

Abstract:

Aiming at the security vulnerability problem of Hadoop platform,this paper analyzes the present security situation of Hadoop platform,puts forward the remaining security hidden trouble,and designs and implements the relevant reinforcement scheme.By integrating the Hadoop authentication system with the highly available enterprise identity management system,the user and authority information of the enterprise security system is unified and the authentication efficiency is improved effectively.At the same time,the field-level access control strategy is enabled to enhance the flexibility of data management.The health evaluation system based on cluster resources is established to control the health status of the cluster,which can guarantee the safe operation of the whole Hadoop cluster.Experimental results show that this scheme is feasible and effective.

Key words: Hadoop platform, enterprise security system, high availability, field-level access control, health evaluation system

中图分类号: