Everywhere All at Once: Co-Location Attacks on Public Cloud FaaS
Zirui Neil Zhao, Adam Morrison, Christopher W. Fletcher, Josep Torrellas
Abstract
Microarchitectural side-channel attacks exploit shared hardware resources, posing significant threats to modern systems. A pivotal step in these attacks is achieving physical host colocation between attacker and victim. This step is especially challenging in public cloud environments due to the widespread adoption of the virtual private cloud (VPC) and the ever-growing size of the data centers. Furthermore, the shift towards Function-as-a-Service (FaaS) environments, characterized by dynamic function instance placements and limited control for attackers, compounds this challenge.
In this paper, we present the first comprehensive study on risks of and techniques for co-location attacks in public cloud FaaS environments. We develop two physical host fingerprinting techniques and propose a new, inexpensive methodology for large-scale instance co-location verification. Using these techniques, we analyze how Google Cloud Run places function instances on physical hosts and identify exploitable placement behaviors. Leveraging our findings, we devise an effective strategy for instance launching that achieves 100% probability of co-locating the attacker with at least one victim instance. Moreover, the attacker co-locates with 61%-100% of victim instances in three major Cloud Run data centers.
• Computer systems organization → Cloud computing; • Security and privacy → Side-channel analysis and countermeasures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2ab09076-3c3c-46fc-873b-5714d8807c9dCited by top-tier papers7
- Last-Level Cache Side-Channel Attacks Are Feasible in the Modern Public CloudZirui Neil Zhao, Adam Morrison, Christopher W. Fletcher, Josep TorrellasASPLOS 2024 · 20 citations
- NVBleed: Covert and Side-Channel Attacks on NVIDIA Multi-GPU InterconnectYicheng Zhang, Ravan Nazaraliyev, Sankha Baran Dutta, Andres Marquez et al.CCS 2026 · 6 citations
- Principled Microarchitectural Isolation on Cloud CPUsStavros Volos, Cédric Fournet, Jana Hofmann, Boris Köpf et al.CCS 2024 · 5 citations
- Bit of a Close Talker: A Practical Guide to Serverless Cloud Co-Location AttacksWei Shao, Najmeh Nazari, Behnam Omidi, Setareh Rafatirad et al.NDSS 2026 · 2 citations
- Efficient Memory Side-Channel Protection for Embedding Generation in Machine LearningMuhammad Umar, Akhilesh Parag Marathe, Monami Dutta Gupta, Shubham Jogprakash Ghosh et al.HPCA 2025 · 2 citations
Builds on10
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 357 citations
- SMoTherSpectre: Exploiting Speculative Execution through Port ContentionAtri Bhattacharyya, Alexandra Sandulescu, Matthias Neugschwandtner, Alessandro Sorniotti et al.CCS 2019 · 267 citations
- Port Contention for Fun and ProfitAlejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida García et al.S&P 2019 · 240 citations
- Attack Directories, Not Caches: Side Channel Attacks in a Non-Inclusive WorldMengjia Yan, Read Sprabery, Bhargava Gopireddy, Christopher W. Fletcher et al.S&P 2019 · 201 citations
- Firecracker: Lightweight Virtualization for Serverless ApplicationsAlexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori et al.NSDI 2020 · 197 citations
Related papers
- Gotcha! I Know What You Are Doing on the FPGA Cloud: Fingerprinting Co-Located Cloud FPGA Accelerators via Measuring Communication LinksChongzhou Fang, Ning Miao, Han Wang, Jiacheng Zhou et al.CCS 2023 · 4 citations
- Repttack: Exploiting Cloud Schedulers to Guide Co-Location AttacksChongzhou Fang, Han Wang, Najmeh Nazari, Behnam Omidi et al.NDSS 2022
- Ohm's Law in Data Centers: A Voltage Side Channel for Timing Power AttacksMohammad A. Islam, Shaolei RenCCS 2018 · 27 citations
- PROBE+DETECT+MITIGATE (PDM): Enabling Cloud Tenants to Self-Defend against Microarchitectural AttacksArash Daneshmand, Hugo Kermabon-Bobinnec, Lingyu Wang, Makan Pourzandi et al.USENIX Security 2026
- HeteroScore: Evaluating and Mitigating Cloud Security Threats Brought by HeterogeneityChongzhou Fang, Najmeh Nazari, Behnam Omidi, Han Wang et al.NDSS 2023
