Lune

USENIX Security2022Top-tier venue

Using Trātṛ to tame Adversarial Synchronization

Yuvraj Patel, Chenhao Ye, Akshat Sinha, Abigail Matthews, Andrea C. Arpaci-Dusseau, Michael M. Swift

2022Year

Abstract

We show that Linux containers are vulnerable to a new class of attacks -synchronization attacks -that exploit kernel synchronization to harm application performance, where an unprivileged attacker can control the duration of kernel critical sections to stall victims running in other containers on the same operating system. Furthermore, a subset of these attacks -framing attacks -persistently harm performance by expanding data structures even after the attacker quiesces. We demonstrate three such attacks on the Linux kernel involving the inode cache, the directory cache, and the futex table. We design Trātr . , a Linux kernel extension, to detect and mitigate synchronization and framing attacks with low overhead, prevent attacks from worsening, and recover by repairing data structures to their pre-attack state. Using microbenchmarks and real-world workloads, we show that Trātr . can detect an attack within seconds and recover instantaneously, guaranteeing similar performance to baseline. Our experiments show that Trātr . can detect simultaneous attacks and mitigate them with minimal overhead.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 20e5fdf9-2421-49fe-a1eb-e3c29549d6ab

Builds on4

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines