Repttack: Exploiting Cloud Schedulers to Guide Co-Location Attacks
Chongzhou Fang, Han Wang, Najmeh Nazari, Behnam Omidi, Avesta Sasan, Khaled N. Khasawneh, Setareh Rafatirad, Houman Homayoun
Abstract
Cloud computing paradigms have emerged as a major facility to store and process the massive data produced by various business units, public organizations, Internet-of-Things, and cyber-physical systems. To meet users' performance requirements while maximizing resource utilization to achieve cost-efficiency, cloud administrators leverage schedulers to orchestrate tasks to different physical nodes and allow applications from different users to share the same physical node. On the other hand, micro-architectural attacks can exploit the shared resources to compromise the confidentiality/integrity of a co-located victim application. Since co-location is an essential requirement for micro-architectural attacks, in this work, we investigate whether attackers can exploit the cloud schedulers to satisfy the co-location requirement. Our analysis shows that for cloud schedulers that allow users to submit application requirements, an attacker can carefully select the attacker's application requirements to influence the scheduler to co-locate it with a targeted victim application. We call such attack Replication Attack (Repttack). Our experimental results, in both a simulated cluster environment and a real cluster, show similar trends; a single attack instance can reach up to 50% co-location rate and with only 5 instances the co-location rate can reach up to 80%. Furthermore, we propose and evaluate a mitigation strategy that can help defend against Repttack. We believe that our results highlight the fact that schedulers in multi-user clusters need to be more carefully designed with security in mind, and the process of making scheduling decisions should involve as little user-defined information as possible.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7be152d9-6019-406e-86f4-2d9747a03540Cited by top-tier papers5
- Everywhere All at Once: Co-Location Attacks on Public Cloud FaaSZirui Neil Zhao, Adam Morrison, Christopher W. Fletcher, Josep TorrellasASPLOS 2024 · 16 citations
- NVBleed: Covert and Side-Channel Attacks on NVIDIA Multi-GPU InterconnectYicheng Zhang, Ravan Nazaraliyev, Sankha Baran Dutta, Andres Marquez et al.CCS 2026 · 6 citations
- Gotcha! I Know What You Are Doing on the FPGA Cloud: Fingerprinting Co-Located Cloud FPGA Accelerators via Measuring Communication LinksChongzhou Fang, Ning Miao, Han Wang, Jiacheng Zhou et al.CCS 2023 · 4 citations
- Bit of a Close Talker: A Practical Guide to Serverless Cloud Co-Location AttacksWei Shao, Najmeh Nazari, Behnam Omidi, Setareh Rafatirad et al.NDSS 2026 · 2 citations
- HeteroScore: Evaluating and Mitigating Cloud Security Threats Brought by HeterogeneityChongzhou Fang, Najmeh Nazari, Behnam Omidi, Han Wang et al.NDSS 2023
Builds on8
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
- Protean: VM Allocation Service at ScaleOri Hadary, Luke Marshall, Ishai Menache, Abhisek Pan et al.OSDI 2020 · 189 citations
- Prime+Abort: A Timer-Free High-Precision L3 Cache Attack using Intel TSXCraig Disselkoen, David Kohlbrenner, Leo Porter, Dean M. TullsenUSENIX Security 2017 · 186 citations
Related papers
- Heat Behind the Meter: A Hidden Threat of Thermal Attacks in Edge Colocation Data CentersZhihui Shao, Mohammad A. Islam, Shaolei RenHPCA 2021 · 10 citations
- Tornadoes In The Cloud: Worst-Case Attacks on Distributed Resources SystemsJhonatan Tavori, Hanoch LevyINFOCOM 2021 · 4 citations
- PROBE+DETECT+MITIGATE (PDM): Enabling Cloud Tenants to Self-Defend against Microarchitectural AttacksArash Daneshmand, Hugo Kermabon-Bobinnec, Lingyu Wang, Makan Pourzandi et al.USENIX Security 2026
- UFO: The Ultimate QoS-Aware Core Management for Virtualized and Oversubscribed Public CloudsYajuan Peng, Shuang Chen, Yi Zhao, Zhibin YuNSDI 2024 · 7 citations
- Who's Afraid of Butterflies? A Close Examination of the Butterfly AttackSanjoy K. Baruah, Pontus Ekberg, Mehdi Hosseinzadeh, Ao Li et al.RTSS 2023 · 4 citations
