Show simple item record

dc.contributor.authorRaknes, Inge Alexander
dc.contributor.authorFjukstad, Bjørn
dc.contributor.authorBongo, Lars Ailo Aslaksen
dc.date.accessioned2021-01-25T14:00:39Z
dc.date.available2021-01-25T14:00:39Z
dc.date.issued2017-11-26
dc.description.abstractData analyses in the life sciences are moving from tools run on a personal computer to services run on large computing platforms. This creates a need to package tools and dependencies for easy installation, configuration and deployment on distributed platforms. In addition, for secure execution there is a need for process isolation on a shared platform. Existing virtual machine and container technologies are often more complex than traditional Unix utilities, like chroot, and often require root privileges in order to set up or use. This is especially challenging on HPC systems where users typically do not have root access. We therefore present nsroot, a lightweight Linux namespaces based process isolation tool. It allows restricting the runtime environment of data analysis tools that may not have been designed with security as a top priority, in order to reduce the risk and consequences of security breaches, without requiring any special privileges. The codebase of nsroot is small, and it provides a command line interface similar to chroot. It can be used on all Linux kernels that implement user namespaces. In addition, we propose combining nsroot with the AppImage format for secure execution of packaged applications. nsroot is open sourced and available at: https://github.com/uit-no/nsroot.en_US
dc.descriptionSource at <a href=https://ojs.bibsys.no/index.php/NIK/article/view/432>https://ojs.bibsys.no/index.php/NIK/article/view/432</a>.en_US
dc.identifier.citationRaknes IA, Fjukstad B, Bongo LA. nsroot: Minimalist process isolation tool implemented with Linux namespaces. NIK: Norsk Informatikkonferanse. 2017en_US
dc.identifier.cristinIDFRIDAID 1522924
dc.identifier.issn1892-0713
dc.identifier.issn1892-0721
dc.identifier.otherhttp://ojs.bibsys.no/index.php/NIK/article/view/432
dc.identifier.urihttps://hdl.handle.net/10037/20478
dc.language.isoengen_US
dc.publisherNorsk Informatikkonferanseen_US
dc.relation.journalNIK: Norsk Informatikkonferanse
dc.rights.accessRightsopenAccessen_US
dc.rights.holderCopyright 2017 The Authorsen_US
dc.subjectVDP::Technology: 500::Information and communication technology: 550en_US
dc.subjectVDP::Teknologi: 500::Informasjons- og kommunikasjonsteknologi: 550en_US
dc.titlensroot: Minimalist process isolation tool implemented with Linux namespacesen_US
dc.type.versionpublishedVersionen_US
dc.typeJournal articleen_US
dc.typeTidsskriftartikkelen_US


File(s) in this item

Thumbnail

This item appears in the following collection(s)

Show simple item record