Querying Container Provenance
Querying Container Provenance
复制标题
查询容器来源
DOI:
10.1145/3543873.3587568
复制
发表时间:
2023
期刊:
影响因子:
--
通讯作者:
Gehani, Ashish
中科院分区:
文献类型:
--
作者:
Modi, Aniket;Reyad, Moaz;Malik, Tanu;Gehani, Ashish
Containers are lightweight mechanisms for the isolation of operating system resources. They are realized by activating a set of namespaces. Given the use of containers in scientific computing, tracking and managing provenance within and across containers is becoming essential for debugging and reproducibility. In this work, we examine the properties of container provenance graphs that result from auditing containerized applications. We observe that the generated container provenance graphs are hypergraphs because one resource may belong to one or more namespaces. We examine the hierarchical behavior of PID, mount, and user namespaces, that are more commonly activated and show that even when represented as hypergraphs, the resulting container provenance graphs are acyclic. We experiment with recently published container logs and identify hypergraph properties.
影响因子:
2.1
作者:
Hale, Jack S.;Li, Lizao;Wells, Garth N.
通讯作者:
Wells, Garth N.
DOI:
--
发表时间:
2020
期刊:
USENIX Theory and Practice of Provenance
影响因子:
--
作者:
Y. Nakamura, T. Malik
通讯作者:
Y. Nakamura, T. Malik
DOI:
--
发表时间:
2013
期刊:
Provenance
影响因子:
--
作者:
L. Moreau;Paul Groth
通讯作者:
Paul Groth