首页> 外文期刊>Concurrency, practice and experience >Sandboxing of biomedical applications in Linux containers based on system call evaluation
【24h】

Sandboxing of biomedical applications in Linux containers based on system call evaluation

机译:基于系统调用评估的Linux容器中生物医学应用程序的沙箱

获取原文
获取原文并翻译 | 示例

摘要

Applications for biomedical data processing often integrate external libraries and frameworks for common algorithmic tasks. It typically reduces development time and increases overall code quality.With the introduction of lightweight container-based virtualization, the bundling of applications and their required dependencies has become feasible, and containers can be transferred and executed in distributed environments.However, the incorporation of unreviewed code poses a security threat as it might contain malicious components. In this paper, measures to minimize risks of untrusted application execution are presented. Based on the system calls issued during sample execution of the application, both the container itself and the container runtime configuration are restricted to the set of actions the application requires. It is shown that the employed security measures are suited to counteract different attacks while application runtime is not affected.
机译:生物医学数据处理的应用程序通常会集成用于常规算法任务的外部库和框架。它通常会减少开发时间并提高整体代码质量。随着基于容器的轻量级虚拟化的引入,应用程序及其所需依赖项的捆绑变得可行,并且可以在分布式环境中传输和执行容器。代码可能会包含恶意组件,因此会构成安全威胁。本文提出了将不可信应用程序执行风险降至最低的措施。基于在应用程序示例执行期间发出的系统调用,容器本身和容器运行时配置都限于应用程序需要的一组操作。结果表明,在不影响应用程序运行时的情况下,所采用的安全措施适用于抵抗不同的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号