With the increasing demand for data storage and the exponential growth of data, traditional single-server architectures are no longer sufficient to handle the massive amounts of data storage, transfer, and various file system events. As a result, distributed file systems have become a necessity to address the scalability challenges of file systems. One such popular distributed file system is Lustre, which is extensively used in high-performance computing environments. Lustre offers parallel file access, allowing multiple clients to access and store data simultaneously. However, in order to ensure the security and integrity of data, auditing plays a crucial role. Lustre auditing serves as a proof of security and enables the implementation of robust security features such as authentication with Kerberos, mandatory access control with SELinux, isolation, and more. Auditing helps track and monitor file system activities, providing valuable insights into user actions, system events, and potential security breaches. The objective of this project is to explore Lustre auditing using CentOS, a popular Linux distribution, within a Lustre architecture. By implementing Lustre auditing, we aim to enhance the security and reliability of the file system. Additionally, we plan to develop a graphical interface that presents the auditing features in a user-friendly and visually appealing manner. This interface will provide administrators and users with a convenient way to monitor and analyze auditing logs, view access patterns, detect anomalies, and ensure compliance with security policies. By combining the power of Lustre's parallel file system architecture with comprehensive auditing capabilities and an intuitive graphical interface, we aim to provide a robust and user-friendly solution for managing and securing large-scale data storage and access.
翻译:随着数据存储需求的持续增长以及数据的指数级膨胀,传统的单服务器架构已无法应对海量数据存储、传输及各种文件系统事件的处理。因此,分布式文件系统已成为解决文件系统可扩展性挑战的必然选择。Lustre就是这样一种广泛使用的分布式文件系统,在高性能计算环境中应用尤为普遍。Lustre支持并行文件访问,允许客户端同时存取数据。然而,为确保数据的安全性与完整性,审计机制发挥着关键作用。Lustre审计可作为安全性的验证手段,并支持实现Kerberos身份认证、SELinux强制访问控制、隔离机制等强大安全功能。审计有助于追踪和监控文件系统活动,为用户操作、系统事件及潜在安全威胁提供关键洞察。本项目的目标是在基于流行Linux发行版CentOS的Lustre架构中探索审计功能。通过实施Lustre审计,我们旨在提升文件系统的安全性与可靠性。此外,我们计划开发一个图形化界面,以用户友好且直观的方式呈现审计特性。该界面将为管理员和用户提供便捷的审计日志监控与分析途径,支持访问模式查看、异常检测及安全策略合规性验证。通过融合Lustre并行文件系统架构的强大性能、全面的审计功能与直观的图形界面,我们致力于为大规模数据存储与访问管理提供兼具健壮性与易用性的解决方案。