The RAppArmor Package: Enforcing Security Policies in R Using Dynamic Sandboxing on Linux

The RAppArmor Package: Enforcing Security Policies in R Using Dynamic Sandboxing on Linux
复制标题

RAppArmor 包:在 Linux 上使用动态沙箱在 R 中实施安全策略

DOI:
--
复制
发表时间:
2013
期刊:
arXiv.org
影响因子:
--
通讯作者:
Jeroen Ooms
Jeroen Ooms
中科院分区:
--
文献类型:
--
作者:
Jeroen Ooms

文献摘要

被引文献

相似文献

云计算和科学超级计算机的日益可用性为通过公共或共享资源访问R带来了巨大的潜力。这使我们能够有效地运行需要大量周期和内存的代码,或者将R功能嵌入到,例如,系统和Web服务。然而,在将其投入生产之前,需要解决一些重要的安全问题。R设计的主要用例一直是一个统计员通过交互式控制台在本地机器上运行R。因此,R的执行环境是完全不受限制的,这可能导致恶意行为或过度使用共享环境中的硬件资源。正确地保护R进程是一个复杂的问题。我们描述了各种方法,并说明了潜在的问题,使用我们的一些个人经验,在托管公共Web服务。最后,我们介绍了RAppArmor包:一个基于Linux的参考实现,用于在操作系统级别上使用R进行动态沙箱。
The increasing availability of cloud computing and scientific super computers brings great potential for making R accessible through public or shared resources. This allows us to efficiently run code requiring lots of cycles and memory, or embed R functionality into, e.g., systems and web services. However some important security concerns need to be addressed before this can be put in production. The prime use case in the design of R has always been a single statistician running R on the local machine through the interactive console. Therefore the execution environment of R is entirely unrestricted, which could result in malicious behavior or excessive use of hardware resources in a shared environment. Properly securing an R process turns out to be a complex problem. We describe various approaches and illustrate potential issues using some of our personal experiences in hosting public web services. Finally we introduce the RAppArmor package: a Linux based reference implementation for dynamic sandboxing in R on the level of the operating system.