Groundhog: Efficient Request Isolation in FaaS
Mohamed Alzayat, Jonathan Mace, Peter Druschel, Deepak Garg
Abstract
Security is a core responsibility for Function-as-a-Service (FaaS) providers. The prevailing approach has each function execute in its own container to isolate concurrent executions of different functions. However, successive invocations of the same function commonly reuse the runtime state of a previous invocation in order to avoid container cold-start delays when invoking a function. Although efficient, this container reuse has security implications for functions that are invoked on behalf of differently privileged users or administrative domains: bugs in a function's implementation, third-party library, or the language runtime may leak private data from one invocation of the function to subsequent invocations of the same function.
Groundhog isolates sequential invocations of a function by efficiently reverting to a clean state, free from any private data, after each invocation. The system exploits two properties of typical FaaS platforms: each container executes at most one function at a time and legitimate functions do not retain state across invocations. This enables Groundhog to efficiently snapshot and restore function state between invocations in a manner that is independent of the programming language/runtime and does not require any changes to existing functions, libraries, language runtimes, or OS kernels. We describe the design of Groundhog and its implementation in OpenWhisk, a popular production-grade open-source FaaS framework. On three existing benchmark suites, Groundhog isolates sequential invocations with modest overhead on end-to-end latency (median: 1.5%, 95p: 7%) and throughput (median: 2.5%, 95p: 49.6%), relative to an insecure baseline that reuses the container and runtime state.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8baec931-82b8-44f0-b772-16c273125d75Cited by top-tier papers17
- Optimus: Warming Serverless ML Inference via Inter-Function Model TransformationZicong Hong, Jian Lin, Song Guo, Sifu Luo et al.EuroSys 2024 · 29 citations
- Halfmoon: Log-Optimal Fault-Tolerant Stateful Serverless ComputingSheng Qi, Xuanzhe Liu, Xin JinSOSP 2023 · 16 citations
- TrEnv: Transparently Share Serverless Execution Environments Across Different Functions and NodesJialiang Huang, Mingxing Zhang, Teng Ma, Zheng Liu et al.SOSP 2024 · 14 citations
- Pronghorn: Effective Checkpoint Orchestration for Serverless Hot-StartsSumer Kohli, Shreyas Kharbanda, Rodrigo Bruno, João Carreira et al.EuroSys 2024 · 13 citations
- Ilúvatar: A Fast Control Plane for Serverless ComputingAlexander Fuerst, Abdul Rehman, Prateek SharmaHPDC 2023 · 10 citations
Builds on4
- Serverless in the Wild: Characterizing and Optimizing the Serverless Workload at a Large Cloud ProviderMohammad Shahrad, Rodrigo Fonseca, Iñigo Goiri, Gohar Irfan Chaudhry et al.USENIX ATC 2020 · 946 citations
- Faasm: Lightweight Isolation for Efficient Stateful Serverless ComputingSimon Shillaker, Peter R. PietzuchUSENIX ATC 2020 · 382 citations
- Catalyzer: Sub-millisecond Startup for Serverless Computing with Initialization-less BootingDong Du, Tianyi Yu, Yubin Xia, Binyu Zang et al.ASPLOS 2020 · 280 citations
- SEUSS: skip redundant paths to make serverless fastJames Cadden, Thomas Unger, Yara Awad, Han Dong et al.EuroSys 2020 · 156 citations
Related papers
- Faastlane: Accelerating Function-as-a-Service WorkflowsSwaroop Kotni, Ajay Nayak, Vinod Ganapathy, Arkaprava BasuUSENIX ATC 2021 · 142 citations
- Canary: Fault-Tolerant FaaS for Stateful Time-Sensitive ApplicationsMoiz Arif, Kevin Assogba, M. Mustafa RafiqueSC 2022 · 9 citations
- OFC: an opportunistic caching system for FaaS platformsDjob Mvondo, Mathieu Bacou, Kevin Nguetchouang, Lucien Ngale et al.EuroSys 2021 · 80 citations
- ALASTOR: Reconstructing the Provenance of Serverless IntrusionsPubali Datta, Isaac Polinsky, Muhammad Adil Inam, Adam Bates et al.USENIX Security 2022
- FaasCache: keeping serverless computing alive with greedy-dual cachingAlexander Fuerst, Prateek SharmaASPLOS 2021 · 223 citations
