Houdini's Escape: Breaking the Resource Rein of Linux Control Groups
Xing Gao, Zhongshu Gu, Zhengfa Li, Hani Jamjoom, Cong Wang
Abstract
Linux Control Groups, i.e., cgroups, are the key building blocks to enable operating-system-level containerization. The cgroups mechanism partitions processes into hierarchical groups and applies different controllers to manage system resources, including CPU, memory, block I/O, etc. Newly spawned child processes automatically copy cgroups attributes from their parents to enforce resource control. Unfortunately, inherited cgroups confinement via process creation does not always guarantee consistent and fair resource accounting. In this paper, we devise a set of exploiting strategies to generate out-of-band workloads via de-associating processes from their original process groups. The system resources consumed by such workloads will not be charged to the appropriate cgroups. To further demonstrate the feasibility, we present five case studies within Docker containers to demonstrate how to break the resource rein of cgroups in realistic scenarios. Even worse, by exploiting those cgroups' insufficiencies in a multi-tenant container environment, an adversarial container is able to greatly amplify the amount of consumed resources, significantly slow-down other containers on the same host, and gain extra unfair advantages on the system resources. We conduct extensive experiments on both a local testbed and an Amazon EC2 cloud dedicated server. The experimental results demonstrate that a container can consume system resources (e.g., CPU) as much as 200× of its limit, and reduce both computing and I/O performance of particular workloads in other co-resident containers by 95%. CCS CONCEPTS • Security and privacy → Virtualization and security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 28b615fa-6b7b-4a7b-97e2-1ae00f8ed135Cited by top-tier papers12
- Demons in the Shared Kernel: Abstract Resource Attacks Against OS-level VirtualizationNanzi Yang, Wenbo Shen, Jinku Li, Yutian Yang et al.CCS 2021 · 32 citations
- SoK: A Comprehensive Analysis and Evaluation of Docker Container Attack and Defense MechanismsMd. Sadun Haq, Thien Duc Nguyen, Ali Saman Tosun, Franziska Vollmer et al.S&P 2024 · 17 citations
- Sync+Sync: A Covert Channel Built on fsync with StorageQisheng Jiang, Chundong WangUSENIX Security 2024 · 12 citations
- Crossing Shifted Moats: Replacing Old Bridges with New Tunnels to Confidential ContainersEnriquillo Valdez, Salman Ahmed, Zhongshu Gu, Christophe de Dinechin et al.CCS 2024 · 4 citations
- JANUS: Cross-World, Cooperative Nested Virtualization for Secure ContainersJiangshan Lai, Hang Huang, Quan Xu, Zhen Ren et al.OSDI 2026
Builds on8
- One Bit Flips, One Cloud Flops: Cross-VM Row Hammer Attacks and Privilege EscalationYuan Xiao, Xiaokuan Zhang, Yinqian Zhang, Radu TeodorescuUSENIX Security 2016 · 272 citations
- A Software Approach to Defeating Side Channels in Last-Level CachesZiqiao Zhou, Michael K. Reiter, Yinqian ZhangCCS 2016 · 155 citations
- Security Namespace: Making Linux Security Frameworks Available to ContainersYuqiong Sun, David Safford, Mimi Zohar, Dimitrios Pendarakis et al.USENIX Security 2018 · 79 citations
- Covert Channels through Random Number Generator: Mechanisms, Capacity Estimation and MitigationsDmitry Evtyushkin, Dmitry V. PonomarevCCS 2016 · 75 citations
- Exploiting a Thermal Side Channel for Power Attacks in Multi-Tenant Data CentersMohammad A. Islam, Shaolei Ren, Adam WiermanCCS 2017 · 53 citations
Related papers
- Losing the Beat: Understanding and Mitigating Desynchronization Risks in Container IsolationZhi Li, Zhen Xu, Weijie Liu, XiaoFeng Wang et al.NDSS 2026
- Enjoy the Free Lunch, Someone Paid for Us: Escaping Resource Limits of MicroVM-based ContainersShiwen Wang, Wu Luo, Kaicheng Liu, Zheyuan Xu et al.USENIX Security 2026
- Using Trātṛ to tame Adversarial SynchronizationYuvraj Patel, Chenhao Ye, Akshat Sinha, Abigail Matthews et al.USENIX Security 2022
- Locks as a Resource: Fairly Scheduling Lock Occupation with CFLJonggyu Park, Young Ik EomPPoPP 2024
- Cross Container Attacks: The Bewildered eBPF on CloudsYi He, Roland Guo, Yunlong Xing, Xijia Che et al.USENIX Security 2023
