|
UNIT
5/LECTURE 1 |
||||||||||||||||||||||||||||||||||||
|
Distributed System Structures ·
Types of Distributed Operating Systems ·
Network Structure ·
Network Topology ·
Communication Structure ·
Communication Protocols ·
Robustness ·
Design Issues Chapter Objectives ·
To provide a high-level overview of distributed
systems and the networks that interconnect them ·
To discuss the general structure of distributed
operating systems
Introduction ·
Distributed system is collection of loosely
coupled processors interconnected by a communications network ·
Processors variously called nodes, computers,
machines, hosts Ø Site is
location of the processor ·
Reasons for distributed systems Ø Resource
sharing 4 sharing
and printing files at remote sites 4 processing
information in a distributed database 4 using
remote specialized hardware devices Ø Computation
speedup – load sharing Ø Reliability
– detect and recover from site failure, function transfer, reintegrate failed
site Ø Communication
– message passing A Distributed System Types of Distributed Operating
Systems ·
Network Operating Systems ·
Distributed Operating Systems Network-Operating Systems ·
Users are aware of multiplicity of machines. Access to resources of various machines is
done explicitly by: 1. Remote
logging into the appropriate remote machine (telnet, ssh) 2. Remote
Desktop (Microsoft Windows) 3. Transferring
data from remote machines to local machines, via the File Transfer Protocol
(FTP) mechanism Distributed-Operating Systems ·
Users not aware of multiplicity of machines 1. Access to remote resources similar to
access to local resources ·
Data Migration – transfer data by transferring
entire file, or transferring only those portions of the file necessary for
the immediate task ·
Computation Migration – transfer the computation,
rather than the data, across the system ·
Process Migration – execute an entire process, or
parts of it, at different sites 1. Load
balancing – distribute processes across network to even the workload 2. Computation
speedup – subprocesses can run concurrently on different sites 3. Hardware
preference – process execution may require specialized processor 4. Software
preference – required software may be available at only a particular site 5. Data
access – run process remotely, rather than transfer all data locally Network Structure ·
Local-Area
Network (LAN) – designed to cover small geographical area. 1. Multiaccess
bus, ring, or star network 2. Speed » 10 – 100 megabits/second 3. Broadcast
is fast and cheap 4. Nodes: 4 usually
workstations and/or personal computers 4 a few
(usually one or two) mainframes Depiction of typical LAN ·
Wide-Area
Network (WAN) – links geographically separated sites 1. Point-to-point
connections over long-haul lines (often leased from a phone company) 2. Speed » 1.544 – 45 megbits/second 3. Broadcast
usually requires multiple messages 4. Nodes: 4 usually a
high percentage of mainframes Communication Processors in a
Wide-Area Network Network Topology ·
Sites in the system can be physically connected in
a variety of ways; they are compared with respect to the following criteria: Ø Basic
cost - How expensive is it to link the
various sites in the system? Ø Communication
cost - How long does it take to send a
message from site A to site B? Ø Reliability
- If a link or a site in the system
fails, can the remaining sites still communicate with each other? ·
The various topologies are depicted as graphs
whose nodes correspond to sites Ø An edge
from node A to node B corresponds to a direct connection
between the two sites ·
The following six items depict various network
topologies Network Topology Communication Structure The design of a communication network must
address four basic issues: ·
Naming and name resolution - How do two processes locate each other to
communicate? ·
Routing strategies - How are messages sent through the network? ·
Connection strategies - How do two processes send a sequence of
messages? ·
Contention -
The network is a shared resource, so how do we resolve conflicting
demands for its use? Naming and Name Resolution ·
Name systems in the network ·
Address messages with the process-id ·
Identify processes on remote systems by <host-name,
identifier> pair ·
Domain name service (DNS) – specifies the
naming structure of the hosts, as well as name to address resolution
(Internet) Routing Strategies ·
Fixed
routing - A path from A to B is specified in advance; path changes
only if a hardware failure disables it Ø Since the
shortest path is usually chosen, communication costs are minimized Ø Fixed
routing cannot adapt to load changes Ø Ensures
that messages will be delivered in the order in which they were sent ·
Virtual
circuit - A path from A to B
is fixed for the duration of one session.
Different sessions involving messages from A to B may
have different paths Ø Partial
remedy to adapting to load changes Ø Ensures
that messages will be delivered in the order in which they were sent ·
Dynamic
routing - The path used to send a
message form site A to site B is chosen only when a message is
sent 1. Usually a
site sends a message to another site on the link least used at that
particular time 2. Adapts to
load changes by avoiding routing messages on heavily used path 3. Messages
may arrive out of order 4 This
problem can be remedied by appending a sequence number to each message Connection Strategies ·
Circuit switching - A permanent physical link is established
for the duration of the communication (i.e., telephone system) ·
Message switching - A temporary link is
established for the duration of one message transfer (i.e., post-office
mailing system) ·
Packet switching -
Messages of variable length are divided into fixed-length packets
which are sent to the destination Ø Each packet may take a different path
through the network Ø The
packets must be reassembled into messages as they arrive ·
Circuit switching requires setup time, but incurs
less overhead for shipping each message, and may waste network bandwidth Message and packet switching require less
setup time, but incur more overhead per message
|
||||||||||||||||||||||||||||||||||||
|
UNIT
5/LECTURE 2 |
||||||||||||||||||||||||||||||||||||
|
Contention Several sites may want to
transmit information over a link simultaneously. Techniques to avoid repeated collisions
include: ·
CSMA/CD -
Carrier sense with multiple access (CSMA); collision detection (CD) Ø A site
determines whether another message is currently being transmitted over that
link. If two or more sites begin
transmitting at exactly the same time, then they will register a CD and will
stop transmitting Ø When the
system is very busy, many collisions may occur, and thus performance may be
degraded ·
CSMA/CD is used successfully in the Ethernet
system, the most common network system ·
Token passing -
A unique message type, known as a token, continuously circulates in
the system (usually a ring structure) Ø A site
that wants to transmit information must wait until the token arrives Ø When the
site completes its round of message passing, it retransmits the token Ø A
token-passing scheme is used by some IBM and HP/Apollo systems ·
Message slots - A number of fixed-length message
slots continuously circulate in the system (usually a ring structure) Ø Since a
slot can contain only fixed-sized messages, a single logical message may have
to be broken down into a number of smaller packets, each of which is sent in
a separate slot Ø This
scheme has been adopted in the experimental Cambridge Digital Communication
Ring Communication Protocol The communication network
is partitioned into the following multiple layers: ·
Physical layer – handles the mechanical and
electrical details of the physical transmission of a bit stream ·
Data-link layer – handles the frames, or
fixed-length parts of packets, including any error detection and recovery
that occurred in the physical layer ·
Network layer – provides connections and routes
packets in the communication network, including handling the address of
outgoing packets, decoding the address of incoming packets, and maintaining
routing information for proper response to changing load levels ·
Transport layer – responsible for low-level
network access and for message transfer between clients, including
partitioning messages into packets, maintaining packet order, controlling
flow, and generating physical addresses ·
Session layer – implements sessions, or
process-to-process communications protocols ·
Presentation layer – resolves the differences in
formats among the various sites in the network, including character
conversions, and half duplex/full duplex (echoing) ·
Application layer – interacts directly with the
users’ deals with file transfer, remote-login protocols and electronic mail,
as well as schemas for distributed databases Communication Via ISO Network Model The ISO Protocol Layer The ISO Network Message The TCP/IP Protocol Layers Robustness ·
Failure detection ·
Reconfiguration Failure Detection ·
Detecting hardware failure is difficult ·
To detect a link failure, a handshaking protocol
can be used ·
Assume Site A and Site B have established a link Ø At fixed intervals, each site will exchange
an I-am-up message indicating that they are up and running ·
If Site A does not receive a message within the
fixed interval, it assumes either (a) the other site is not up or (b) the
message was lost ·
Site A can now send an Are-you-up? message
to Site B ·
If Site A does not receive a reply, it can repeat
the message or try an alternate route to Site B ·
If Site A does not ultimately receive a reply from
Site B, it concludes some type of failure has occurred ·
Types of failures: - The direct link between A and B is down - The message has been lost ·
However, Site A cannot determine exactly why the
failure has occurred
|
||||||||||||||||||||||||||||||||||||
|
UNIT
5/LECTURE 3 |
||||||||||||||||||||||||||||||||||||
|
Reconfiguration ·
When Site A determines a failure has occurred, it
must reconfigure the system: 1. If the link from A to B has failed, this must be
broadcast to every site in the system 2. If a site has failed, every other site must also be
notified indicating that the services
offered by the failed site
are no longer available When the link or the site becomes available
again, this information must again be broadcast to all other sites ·
Transparency – the distributed system should
appear as a conventional, centralized system to the user ·
Fault tolerance – the distributed system should
continue to function in the face of failure ·
Scalability – as demands increase, the system
should easily accept the addition of new resources to accommodate the
increased demand ·
Clusters – a collection of semi-autonomous
machines that acts as a single system Example: Networking ·
The transmission of a network packet between hosts
on an Ethernet network ·
Every host has a unique IP address and a
corresponding Ethernet (MAC) address ·
Communication requires both addresses ·
Domain Name Service (DNS) can be used to acquire
IP addresses ·
Address Resolution Protocol (ARP) is used to map
MAC addresses to IP addresses ·
If the hosts are on the same network, ARP can be
used Ø If the
hosts are on different networks, the sending host will send the packet to a router
which routes the packet to the destination network An Ethernet Packet Distributed-File Systems ·
Background ·
Naming and Transparency ·
Remote File Access ·
Stateful versus Stateless Service ·
File Replication Objectives ·
To explain the naming mechanism that provides
location transparency and independence ·
To describe the various methods for accessing
distributed files ·
To contrast stateful and stateless distributed
file servers ·
To show how replication of files on different
machines in a distributed file system is a useful redundancy for improving
availability ·
To introduce the Andrew file system (AFS) as an
example of a distributed file system Background ·
Distributed file system (DFS) – a distributed
implementation of the classical time-sharing model of a file system, where
multiple users share files and storage resources ·
A DFS manages set of dispersed storage devices ·
Overall storage space managed by a DFS is composed
of different, remotely located, smaller storage spaces ·
There is usually a correspondence between
constituent storage spaces and sets of files DFS Structure ·
Service – software entity running on one or more
machines and providing a particular type of function to a priori unknown
clients ·
Server – service software running on a single
machine ·
Client –
process that can invoke a service using a set of operations that forms
its client interface ·
A client interface for a file service is formed by
a set of primitive file operations (create, delete, read, write) ·
Client interface of a DFS should be transparent,
i.e., not distinguish between local and remote files Naming and Transparency ·
Naming – mapping between logical and physical
objects ·
Multilevel mapping – abstraction of a file that
hides the details of how and where on the disk the file is actually stored ·
A transparent DFS hides the location where in the
network the file is stored ·
For a file being replicated in several sites, the
mapping returns a set of the locations of this file’s replicas; both the
existence of multiple copies and their location are hidden Naming Structures ·
Location transparency – file name does not reveal the file’s
physical storage location ·
Location independence – file name does not need to
be changed when the file’s physical storage location changes Naming Schemes — Three Main
Approaches ·
Files named by combination of their host name and
local name; guarantees a unique systemwide name ·
Attach remote directories to local directories,
giving the appearance of a coherent directory tree; only previously mounted
remote directories can be accessed transparently ·
Total integration of the component file systems Ø A single global
name structure spans all the files in the system Ø If a
server is unavailable, some arbitrary set of directories on different
machines also becomes unavailable Remote File Access ·
Remote-service mechanism is one transfer approach ·
Reduce network traffic by retaining recently
accessed disk blocks in a cache, so that repeated accesses to the same
information can be handled locally Ø If needed
data not already cached, a copy of data is brought from the server to the
user Ø Accesses
are performed on the cached copy Ø Files
identified with one master copy residing at the server machine, but copies of
(parts of) the file are scattered in different caches Ø Cache-consistency
problem – keeping the cached copies consistent with the master file 4 Could be
called network virtual memory Cache Location – Disk vs. Main
Memory ·
Advantages of disk caches Ø More
reliable Ø Cached
data kept on disk are still there during recovery and don’t need to be
fetched again ·
Advantages of main-memory caches: Ø Permit
workstations to be diskless Ø Data can
be accessed more quickly Ø Performance
speedup in bigger memories Ø Server
caches (used to speed up disk I/O) are in main memory regardless of where
user caches are located; using main-memory caches on the user machine permits
a single caching mechanism for servers and users Cache Update Policy ·
Write-through – write data through to disk as soon
as they are placed on any cache Ø Reliable,
but poor performance ·
Delayed-write – modifications written to the cache
and then written through to the server later Ø Write accesses complete quickly; some data
may be overwritten before they are written back, and so need never be written
at all Ø Poor
reliability; unwritten data will be lost whenever a user machine crashes Ø Variation
– scan cache at regular intervals and flush blocks that have been modified
since the last scan Ø Variation
– write-on-close, writes data back to the server when the file is closed 4 Best for
files that are open for long periods and frequently modified
|
||||||||||||||||||||||||||||||||||||
|
NIT
5/LECTURE 4 |
||||||||||||||||||||||||||||||||||||
|
Caches and its Use of Caching Consistency ·
Is locally cached copy of the data consistent with
the master copy? ·
Client-initiated approach Ø Client
initiates a validity check Ø Server
checks whether the local data are consistent with the master copy ·
Server-initiated approach Ø Server
records, for each client, the (parts of) files it caches Ø When
server detects a potential inconsistency, it must react Comparing Caching and Remote
Service ·
In caching, many remote accesses handled efficiently
by the local cache; most remote accesses will be served as fast as local ones
·
Servers are contracted only occasionally in
caching (rather than for each access) Ø Reduces
server load and network traffic Ø Enhances
potential for scalability ·
Remote server method handles every remote access
across the network; penalty in network traffic, server load, and performance ·
Total network overhead in transmitting big chunks
of data (caching) is lower than a series of responses to specific requests
(remote-service) ·
Caching is superior in access patterns with
infrequent writes Ø With
frequent writes, substantial overhead incurred to overcome cache-consistency
problem ·
Benefit from caching when execution carried out on
machines with either local disks or large main memories ·
Remote access on diskless, small-memory-capacity
machines should be done through remote-service method ·
In caching, the lower intermachine interface is
different form the upper user interface ·
In remote-service, the intermachine interface
mirrors the local user-file-system interface Stateful File Service ·
Mechanism Ø Client
opens a file Ø Server
fetches information about the file from its disk, stores it in its memory,
and gives the client a connection identifier unique to the client and the
open file Ø Identifier
is used for subsequent accesses until the session ends Ø Server
must reclaim the main-memory space used by clients who are no longer active ·
Increased
performance Ø Fewer
disk accesses Ø Stateful
server knows if a file was opened for sequential access and can thus read
ahead the next blocks Stateless File Server ·
Avoids state information by making each request
self-contained ·
Each request identifies the file and position in
the file ·
No need to establish and terminate a connection by
open and close operations Distinctions Between Stateful &
Stateless Service ·
Failure Recovery Ø A
stateful server loses all its volatile state in a crash 4 Restore
state by recovery protocol based on a dialog with clients, or abort
operations that were underway when the crash occurred 4 Server
needs to be aware of client failures in order to reclaim space allocated to
record the state of crashed client processes (orphan detection and
elimination) Ø With
stateless server, the effects of server failure sand recovery are almost
unnoticeable 4 A newly
reincarnated server can respond to a self-contained request without any
difficulty ·
Penalties for using the robust stateless service: Ø longer
request messages Ø slower
request processing Ø additional
constraints imposed on DFS design ·
Some environments require stateful service Ø A server
employing server-initiated cache validation cannot provide stateless service,
since it maintains a record of which files are cached by which clients Ø UNIX use
of file descriptors and implicit offsets is inherently stateful; servers must
maintain tables to map the file descriptors to inodes, and store the current
offset within a file File Replication ·
Replicas of the same file reside on
failure-independent machines ·
Improves availability and can shorten service time ·
Naming scheme maps a replicated file name to a
particular replica Ø Existence
of replicas should be invisible to higher levels Ø Replicas
must be distinguished from one another by different lower-level names ·
Updates – replicas of a file denote the same
logical entity, and thus an update to any replica must be reflected on all
other replicas ·
Demand replication – reading a nonlocal replica
causes it to be cached locally, thereby generating a new nonprimary replica.
|
||||||||||||||||||||||||||||||||||||
|
UNIT
5/LECTURE 5 |
||||||||||||||||||||||||||||||||||||
|
Security
Objectives
The Security Problem
Security Violations
Ø
Breach of confidentiality Ø
Breach of integrity Ø
Breach of availability Ø
Theft of service Ø
Denial of service
Ø
Masquerading (breach authentication) Ø
Replay attack 4
Message modification Ø
Man-in-the-middle attack Ø
Session hijacking Standard Security Attacks Security Measure Levels
Ø Physical Ø Human 4 Avoid
social engineering, phishing, dumpster diving Ø Operating
System Ø Network
Program Threats
Ø Code
segment that misuses its environment Ø Exploits
mechanisms for allowing programs written by users to be executed by other
users Ø Spyware,
pop-up browser windows, covert channels
Ø Specific
user identifier or password that circumvents normal security procedures Ø Could be
included in a compiler
Ø Program
that initiates a security incident under certain circumstances
Ø Exploits
a bug in a program (overflow either the stack or memory buffers)
Ø Code
fragment embedded in legitimate program Ø Very
specific to CPU architecture, operating system, applications Ø Usually
borne via email or as a macro
A Boot-sector Computer Virus System and Network Threats
Ø Exploited
UNIX networking features (remote access) and bugs in finger and sendmail
programs Ø Grappling
hook program uploaded main worm program
Ø Automated
attempt to connect to a range of ports on one or a range of IP addresses
Ø Overload
the targeted computer preventing it from doing any useful work Ø Distributed
denial-of-service (DDOS) come from multiple sites at once Cryptography as a Security Tool
Ø Source
and destination of messages cannot be trusted without cryptography Ø Means to
constrain potential senders (sources) and / or receivers (destinations)
of messages
Secure Communication over Insecure
Medium
|
||||||||||||||||||||||||||||||||||||
|
UNIT
4/LECTURE 6 |
||||||||||||||||||||||||||||||||||||||||
|
Encryption
Ø Set of K
keys Ø Set of M
Messages Ø Set of C
ciphertexts (encrypted messages) Ø A
function E : K → (M→C). That is, for
each k Î K, E(k)
is a function for generating ciphertexts from messages. 1. Both E
and E(k) for any k should be efficiently computable
functions. Ø A
function D : K → (C → M). That is,
for each k Î K,
D(k) is a function for generating messages from ciphertexts. 1. Both D
and D(k) for any k should be efficiently computable
functions.
Ø Thus, a
computer holding D(k) can decrypt ciphertexts to the plaintexts
used to produce them, but a computer not holding D(k) cannot
decrypt ciphertexts. Ø Since
ciphertexts are generally exposed (for example, sent on the network), it is
important that it be infeasible to derive D(k) from the
ciphertexts Symmetric Encryption
Ø E(k)
can be derived from D(k), and vice versa
Ø Encrypts
a block of data at a time
Ø Encrypts/decrypts
a stream of bytes (i.e wireless transmission) Ø Key is a
input to psuedo-random-bit generator 4 Generates
an infinite keystream Asymmetric Encryption
Ø public
key – published key used to encrypt data Ø private
key – key known only to individual user used to decrypt data
Ø Most
common is RSA block cipher Ø Efficient
algorithm for testing whether or not a number is prime Ø No
efficient algorithm is know for finding the prime factors of a number
Ø Asymmetric
much more compute intensive Ø Typically
not used for bulk data encryption Authentication
4 That is,
for each k Î K, S(k)
is a function for generating authenticators from messages 4 Both S
and S(k) for any k should be efficiently computable
functions
4 Both V
and V(k) for any k should be efficiently computable
functions
Authentication – Hash Functions
Ø Must be
infeasible to find an m’ ≠ m such that H(m)
= H(m’)
Ø The
message has not been modified
Key Distribution
Man-in-the-middle Attack on
Asymmetric Cryptography Digital Certificates
Ø They
vouch for other authorities via digitally signing their keys, and so on User Authentication
Ø Also can
include something user has and /or a user attribute
Ø Frequent
change of passwords Ø Use of
“non-guessable” passwords Ø Log all
invalid access attempts
Implementing Security Defenses
Ø Signature-based
detection spots known bad patterns Ø Anomaly
detection spots differences from normal behavior 4 Can
detect zero-day attacks Ø False-positives
and false-negatives a problem
Firewalling to Protect Systems and
Networks
Ø The
firewall limits network access between these two security domains
Ø Tunneling
allows disallowed protocol to travel within allowed protocol (i.e. telnet
inside of HTTP) Ø Firewall
rules typically based on host name or IP address which can be spoofed
Ø Can
monitor / limit traffic to and from the host
Network Security Through Domain
Separation Via Firewall Computer Security Classifications
|
||||||||||||||||||||||||||||||||||||||||