Published in

12th IFIP/IEEE International Symposium on Integrated Network Management (IM 2011) and Workshops

DOI: 10.1109/inm.2011.5990711

Links

Tools

Export citation

Search in Google Scholar

An experimental testbed to predict the performance of XACML Policy Decision Points.

Proceedings article published in 2011 by Bernard Butler, Brendan Jennings ORCID, Dmitri Botvich
This paper is available in a repository.
This paper is available in a repository.

Full text: Download

Green circle
Preprint: archiving allowed
Green circle
Postprint: archiving allowed
Red circle
Published version: archiving forbidden
Data provided by SHERPA/RoMEO

Abstract

content management systems. This paper describes how an (offline) experimental testbed may be used to address performance concerns. To begin, timing mea­ surements are collected from a server component incorporating the Policy Decision Point (PDP) under test, using representative policies and corresponding requests. Our experiments with two XACML PDP implementations show that measured request service times are typically clustered by request type; thus an algorithm for request cluster identification is presented. Cluster characterisation s are used as inputs to a PDP performance model for a given policy/request mix and an analytic (queueing) model is used to estimate the equilibrium server load for different mixes of request clusters. The analytic performance prediction model is validated and extended by discrete event simulation of a PDP subject to additional load. These predictive models enable network administrators to explore the capacity of the PDP for different overall loadings (requests per unit time) and profiles (relative frequencies) of requests.