Repository logo

DVAS: dynamic vulnerability-aware scheduling for HPC clusters using Splunk-driven access control

dc.contributor.authorChawla, Abhimanyu, author
dc.contributor.authorRay, Indrakshi, author
dc.contributor.authorACM, publisher
dc.date.accessioned2026-09-17T18:25:59Z
dc.date.issued2026-07-08
dc.description.abstractHigh Performance Computing (HPC) environments are increasingly being considered as high-value target for attackers. Vulnerabilities identified in such environments cannot be immediately patched because of the need for high system availability and long-running workflows. If jobs execute on vulnerable nodes, the value of the output produced are suspect. Moreover, if vulnerable nodes are completely excluded from job allocation, the throughput of the system is affected. Towards this end, we propose DVAS, a dynamic vulnerability-aware scheduling mechanism that aims to maximize throughput taking into account the risk caused by vulnerabilities. DVAS correlates real-time vulnerability telemetry with user behavioral profiling to calculate a probabilistic risk score which is used as a dynamic attribute for controlling access to compute nodes in an HPC cluster. DVAS is implemented using our proposed Secure Job Admission (SJA) algorithm that uses Splunk analytics. We use an asynchronous architecture that decouples the Policy Decision Point (PDP) from the Policy Enforcement Point (PEP), achieving a mean enforcement latency of 0.88ms. Our evaluation on a 25-node cluster shows that DVAS reduces risk exposure by 98% while maintaining 91.8% utilization, significantly outperforming traditional ''drain-and-patch'' strategies. We also propose a measure called Security-Weighted Throughput (SWT) of a cluster that maps security into an operational cost and determines the throughput taking into account the untrustworthiness of results produced by execution on a node containing exploitable vulnerabilities.
dc.format.mediumborn digital
dc.format.mediumarticles
dc.identifierFACF_ACMOA_3750555.3811898.pdf
dc.identifier.bibliographicCitationAbhimanyu Chawla and Indrakshi Ray. 2026. DVAS: Dynamic Vulnerability- Aware Scheduling for HPC Clusters using Splunk-Driven Access Control. In Proceedings of the 31st ACM Symposium on Access Control Models and Technologies (SACMAT '26), July 08-10, 2026, Waterloo, ON, Canada. ACM, New York, NY, USA, 11 pages. https://doi.org/10.1145/3750555.3811898
dc.identifier.doihttps://doi.org/10.1145/3750555.3811898
dc.identifier.urihttps://hdl.handle.net/10217/245553
dc.languageEnglish
dc.language.isoeng
dc.publisherColorado State University. Libraries
dc.relation.ispartofPublications
dc.relation.ispartofACM DL Digital Library
dc.rights.licenseThis work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0
dc.subjectHPC security
dc.subjectSplunk
dc.subjectSLURM
dc.subjectvulnerability-aware access control
dc.subjectbehavioral profiling
dc.titleDVAS: dynamic vulnerability-aware scheduling for HPC clusters using Splunk-driven access control
dc.typeText
dc.typeImage

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
FACF_ACMOA_3750555.3811898.pdf
Size:
1.3 MB
Format:
Adobe Portable Document Format

Collections