DVAS: dynamic vulnerability-aware scheduling for HPC clusters using Splunk-driven access control
| dc.contributor.author | Chawla, Abhimanyu, author | |
| dc.contributor.author | Ray, Indrakshi, author | |
| dc.contributor.author | ACM, publisher | |
| dc.date.accessioned | 2026-09-17T18:25:59Z | |
| dc.date.issued | 2026-07-08 | |
| dc.description.abstract | High Performance Computing (HPC) environments are increasingly being considered as high-value target for attackers. Vulnerabilities identified in such environments cannot be immediately patched because of the need for high system availability and long-running workflows. If jobs execute on vulnerable nodes, the value of the output produced are suspect. Moreover, if vulnerable nodes are completely excluded from job allocation, the throughput of the system is affected. Towards this end, we propose DVAS, a dynamic vulnerability-aware scheduling mechanism that aims to maximize throughput taking into account the risk caused by vulnerabilities. DVAS correlates real-time vulnerability telemetry with user behavioral profiling to calculate a probabilistic risk score which is used as a dynamic attribute for controlling access to compute nodes in an HPC cluster. DVAS is implemented using our proposed Secure Job Admission (SJA) algorithm that uses Splunk analytics. We use an asynchronous architecture that decouples the Policy Decision Point (PDP) from the Policy Enforcement Point (PEP), achieving a mean enforcement latency of 0.88ms. Our evaluation on a 25-node cluster shows that DVAS reduces risk exposure by 98% while maintaining 91.8% utilization, significantly outperforming traditional ''drain-and-patch'' strategies. We also propose a measure called Security-Weighted Throughput (SWT) of a cluster that maps security into an operational cost and determines the throughput taking into account the untrustworthiness of results produced by execution on a node containing exploitable vulnerabilities. | |
| dc.format.medium | born digital | |
| dc.format.medium | articles | |
| dc.identifier | FACF_ACMOA_3750555.3811898.pdf | |
| dc.identifier.bibliographicCitation | Abhimanyu Chawla and Indrakshi Ray. 2026. DVAS: Dynamic Vulnerability- Aware Scheduling for HPC Clusters using Splunk-Driven Access Control. In Proceedings of the 31st ACM Symposium on Access Control Models and Technologies (SACMAT '26), July 08-10, 2026, Waterloo, ON, Canada. ACM, New York, NY, USA, 11 pages. https://doi.org/10.1145/3750555.3811898 | |
| dc.identifier.doi | https://doi.org/10.1145/3750555.3811898 | |
| dc.identifier.uri | https://hdl.handle.net/10217/245553 | |
| dc.language | English | |
| dc.language.iso | eng | |
| dc.publisher | Colorado State University. Libraries | |
| dc.relation.ispartof | Publications | |
| dc.relation.ispartof | ACM DL Digital Library | |
| dc.rights.license | This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License. | |
| dc.rights.uri | https://creativecommons.org/licenses/by-nc-nd/4.0 | |
| dc.subject | HPC security | |
| dc.subject | Splunk | |
| dc.subject | SLURM | |
| dc.subject | vulnerability-aware access control | |
| dc.subject | behavioral profiling | |
| dc.title | DVAS: dynamic vulnerability-aware scheduling for HPC clusters using Splunk-driven access control | |
| dc.type | Text | |
| dc.type | Image |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- FACF_ACMOA_3750555.3811898.pdf
- Size:
- 1.3 MB
- Format:
- Adobe Portable Document Format
