Hadoop Security
Benoy Anthony, Konstantin Boudnik, Cheryl Adams, Branky Shao, Cazen Lee, Kai Sasaki · 2016
This chapter discusses various security features supported by Hadoop. Securing the perimeter of the Hadoop cluster using firewalls is critical to prevent unauthorized requests to Hadoop cluster. The chapter identifies the different types of machines in a Hadoop cluster and discusses the differences in securing the perimeter for these machines. The authentication of users with Kerberos is covered with a detailed overview of the Kerberos protocol. The chapter also covers the first level of authorization available in Hadoop-Service Level Authorization. Impersonating other users securely has many use cases in intermediary services and applications, and the chapter looks at how to secure the HTTP channels with pluggable authentication and SSL. The chapter also covers the methods and configuration to ingest data to a cluster, ensuring integrity and confidentiality using RPC and HTTP protocols. Finally, it covers the usage of secure containers to ensure process isolation during data processing.