Warmonger: Inflicting Denial-of-Service via Serverless Functions in the Cloud
Junjie Xiong, Mingkui Wei, Zhuo Lu, Yao Liu
Abstract
We debut the Warmonger attack, a novel attack vector that can cause denial-of-service between a serverless computing platform and an external content server. The Warmonger attack exploits the fact that a serverless computing platform shares the same set of egress IPs among all serverless functions, which belong to different users, to access an external content server. As a result, a malicious user on this platform can purposefully misbehave and cause these egress IPs to be blocked by the content server, resulting in a platform-wide denial of service. To validate the Warmonger attack, we ran months-long experiments, collected and analyzed the egress IP usage pattern of four major serverless service providers (SSPs). We also conducted an in-depth evaluation of an attacker's possible moves to inflict an external server and cause IP-blockage. We demonstrate that some SSPs use surprisingly small numbers of egress IPs (as little as only four) and share them among their users, and that the serverless platform provides sufficient leverage for a malicious user to conduct well-known misbehaviors and cause IP-blockage. Our study unveiled a potential security threat on the emerging serverless computing platform, and shed light on potential mitigation approaches.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6420cdff-0c98-4b37-9bad-3ce38adb6227Cited by top-tier papers3
- The Dark Side of Flexibility: Detecting Risky Permission Chaining Attacks in Serverless ApplicationsXunqi Liu, Nanzi Yang, Chang Li, Jinku Li et al.NDSS 2026 · 1 citation
- BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the InternetChuhan Wang, Yasuhiro Kuranaga, Yihang Wang, Mingming Zhang et al.NDSS 2024
- Exploring and Analyzing Cross Layer DoS Attack Against UDP-based Services on LinuxDashuai Wu, Yunyi Zhang, Baojun Liu, Xiang Li et al.CCS 2025
Builds on5
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy et al.USENIX Security 2019 · 123 citations
- Valve: Securing Function Workflows on Serverless Computing PlatformsPubali Datta, Prabuddha Kumar, Tristan Morris, Michael Grace et al.WWW 2020 · 79 citations
- Cloud Strife: Mitigating the Security Risks of Domain-Validated CertificatesKevin Borgolte, Tobias Fiebig, Shuang Hao, Christopher Kruegel et al.NDSS 2018 · 63 citations
- BLAG: Improving the Accuracy of BlacklistsSivaramakrishnan Ramanathan, Jelena Mirkovic, Minlan YuNDSS 2020
- CDN Judo: Breaking the CDN DoS Protection with ItselfRun Guo, Weizhong Li, Baojun Liu, Shuang Hao et al.NDSS 2020
Related papers
- Bit of a Close Talker: A Practical Guide to Serverless Cloud Co-Location AttacksWei Shao, Najmeh Nazari, Behnam Omidi, Setareh Rafatirad et al.NDSS 2026 · 2 citations
- Exploiting Miscoordination of Microservices in Tandem for Effective DDoS AttacksAnat Bremler-Barr, Michael Czeizler, Hanoch Levy, Jhonatan TavoriINFOCOM 2024 · 7 citations
- Gringotts: Fast and Accurate Internal Denial-of-Wallet Detection for Serverless ComputingJunxian Shen, Han Zhang, Yantao Geng, Jiawei Li et al.CCS 2022 · 19 citations
- Measuring and Mitigating the Risk of IP Reuse on Public CloudsEric Pauley, Ryan Sheatsley, Blaine Hoak, Quinn Burke et al.S&P 2022 · 22 citations
- ALASTOR: Reconstructing the Provenance of Serverless IntrusionsPubali Datta, Isaac Polinsky, Muhammad Adil Inam, Adam Bates et al.USENIX Security 2022
