Secure Data Analytics in Apache Spark with Fine-grained Policy Enforcement and Isolated Execution
Byeongwook Kim, Jaewon Hur, Adil Ahmad, Byoungyoung Lee
Abstract
—Cloud based Spark platform is a tempting approach for sharing data, as it allows data users to easily analyze the data while the owners to efficiently share the large volume of data. However, the absence of a robust policy enforcement mechanism on Spark hinders the data owners from sharing their data due to the risk of private data breach. In this respect, we found that malicious data users and cloud managers can easily leak the data by constructing a policy violating physical plan, compromising the Spark libraries, or even compromising the Spark cluster itself. Nonetheless, current approaches fail to securely and generally enforce the policies on Spark, as they do not check the policies on physical plan level, and they do not protect the integrity of data analysis pipeline. This paper presents L APUTA 1 , a secure policy enforcement framework on Spark. Specifically, L APUTA designs a pattern matching based policy checking on the physical plans, which is generally applicable to Spark applications with more fine-grained policies. Then, L APUTA compartmentalizes Spark applications based on confidential computing, by which the entire data analysis pipeline is protected from the malicious data users and cloud managers. Meanwhile, L APUTA preserves the usability as the data users can run their Spark applications on L APUTA with minimal modification. We implemented L APUTA , and evaluated its security and performance aspects on TPC-H, Big Data benchmarks, and real world applications using ML models. The evaluation results demonstrated that L APUTA correctly blocks malicious Spark applications while imposing moderate performance overheads.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 31066d2c-b571-4a14-b93c-8bedb69621bbCited by top-tier papers1
Ask how each one uses itBuilds on7
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- OBLIVIATE: A Data Oblivious Filesystem for Intel SGXAdil Ahmad, Kyungtae Kim, Muhammad Ihsanulhaq Sarfaraz, Byoungyoung LeeNDSS 2018 · 144 citations
- Qapla: Policy compliance for database-backed systemsAastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg et al.USENIX Security 2017 · 46 citations
Related papers
- TaintStream: fine-grained taint tracking for big data platforms through dynamic code translationChengxu Yang, Yuanchun Li, Mengwei Xu, Zhenpeng Chen et al.FSE 2021 · 11 citations
- Oblivious coopetitive analytics using hardware enclavesAnkur Dave, Chester Leung, Raluca Ada Popa, Joseph E. Gonzalez et al.EuroSys 2020 · 26 citations
- PICACHV: Formally Verified Data Use Policy Enforcement for Secure Data AnalyticsHaobin Hiroki Chen, Hongbo Chen, Mingshen Sun, Chenghong Wang et al.USENIX Security 2025
- FLARE: A Fast, Secure, and Memory-Efficient Distributed Analytics Framework (Flavor: Systems)Xiang Li, Fabing Li, Mingyu GaoVLDB 2023 · 14 citations
- Generalized Policy-Based Noninterference for Efficient Confidentiality-PreservationShamiek Mangipudi, Pavel Chuprikov, Patrick Eugster, Malte Viering et al.PLDI 2023 · 3 citations
