Querying Container Provenance

Querying Container Provenance
复制标题

查询容器来源

DOI:
10.1145/3543873.3587568
复制
发表时间:
2023
期刊:
WWW '23 Companion: Companion Proceedings of the ACM Web Conference 2023
影响因子:
--
通讯作者:
Gehani, Ashish
Gehani, Ashish
中科院分区:
--
文献类型:
--
作者:
Modi, Aniket;Reyad, Moaz;Malik, Tanu;Gehani, Ashish

文献摘要

参考文献

被引文献

相似文献

容器是用于隔离操作系统资源的轻量级机制。它们是通过激活一组名称空间来实现的。考虑到容器在科学计算中的使用,跟踪和管理容器内和容器之间的出处对于调试和再现性变得至关重要。在这项工作中,我们研究了容器起源图的属性,导致审计容器化的应用程序。我们观察到生成的容器出处图是超图,因为一个资源可能属于一个或多个命名空间。我们研究的PID,挂载,和用户命名空间,更常见的激活,并显示,即使表示为超图的分层行为,由此产生的容器出处图是无环的。我们用最近发布的容器日志进行实验,并确定超图属性。
Containers are lightweight mechanisms for the isolation of operating system resources. They are realized by activating a set of namespaces. Given the use of containers in scientific computing, tracking and managing provenance within and across containers is becoming essential for debugging and reproducibility. In this work, we examine the properties of container provenance graphs that result from auditing containerized applications. We observe that the generated container provenance graphs are hypergraphs because one resource may belong to one or more namespaces. We examine the hierarchical behavior of PID, mount, and user namespaces, that are more commonly activated and show that even when represented as hypergraphs, the resulting container provenance graphs are acyclic. We experiment with recently published container logs and identify hypergraph properties.
DOI: 10.1109/mcse.2017.2421459
发表时间: 2017-11-01
影响因子: 2.1
作者:
Hale, Jack S.;Li, Lizao;Wells, Garth N.
通讯作者: Wells, Garth N.
DOI: --
发表时间: 2020
期刊: USENIX Theory and Practice of Provenance
影响因子: --
作者:
Y. Nakamura, T. Malik
通讯作者: Y. Nakamura, T. Malik
DOI: --
发表时间: 2013
期刊: Provenance
影响因子: --
作者:
L. Moreau;Paul Groth
通讯作者: Paul Groth