Next-generation big data federation access control: A reference model

Feras M. Awaysheh, Mamoun Alazab, Maanak Gupta, Tomás F. Pena, José C. Cabaleiro

Research output: Contribution to journalArticle

Abstract

This paper discusses one of the most significant challenges of next-generation big data (BD) federation platforms, namely, Hadoop access control. Privacy and security on a federation scale remain significant concerns among practitioners in both industry and academia. Hadoop's current primitive access control presents security concerns and limitations, such as the complexity of deployment and the consumption of resources. However, this major concern has not been a subject of intensive study in the literature. This paper critically reviews and investigates these security limitations and provides a framework called BD federation access broker to address 8 main security limitations. This paper proposes the federated access control reference model (FACRM) to formalize the design of secure BD solutions within the Apache Hadoop stack. Furthermore, this paper discusses the implementation of the access broker and its usefulness for security breach detection and digital forensics investigations. The efficiency of the proposed access broker has not sustainably affected the performance overhead. The experimental results show only 1% of each 100 MB read/write operation in a WebHDFS. Overall, the findings of the paper pave the way for a wide range of revolutionary and state-of-the-art enhancements and future trends within Hadoop stack security and privacy.

Original languageEnglish
Pages (from-to)726-741
Number of pages16
JournalFuture Generation Computer Systems
Volume108
DOIs
Publication statusPublished - Jul 2020

Fingerprint Dive into the research topics of 'Next-generation big data federation access control: A reference model'. Together they form a unique fingerprint.

  • Cite this