Houdini's Escape: Breaking the Resource Rein of Linux Control Groups
Xing Gao, Zhongshu Gu, Zhengfa Li, Hani Jamjoom, Cong Wang
摘要
Linux Control Groups, i.e., cgroups, are the key building blocks to enable operating-system-level containerization. The cgroups mechanism partitions processes into hierarchical groups and applies different controllers to manage system resources, including CPU, memory, block I/O, etc. Newly spawned child processes automatically copy cgroups attributes from their parents to enforce resource control. Unfortunately, inherited cgroups confinement via process creation does not always guarantee consistent and fair resource accounting. In this paper, we devise a set of exploiting strategies to generate out-of-band workloads via de-associating processes from their original process groups. The system resources consumed by such workloads will not be charged to the appropriate cgroups. To further demonstrate the feasibility, we present five case studies within Docker containers to demonstrate how to break the resource rein of cgroups in realistic scenarios. Even worse, by exploiting those cgroups' insufficiencies in a multi-tenant container environment, an adversarial container is able to greatly amplify the amount of consumed resources, significantly slow-down other containers on the same host, and gain extra unfair advantages on the system resources. We conduct extensive experiments on both a local testbed and an Amazon EC2 cloud dedicated server. The experimental results demonstrate that a container can consume system resources (e.g., CPU) as much as 200× of its limit, and reduce both computing and I/O performance of particular workloads in other co-resident containers by 95%. CCS CONCEPTS • Security and privacy → Virtualization and security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- Demons in the Shared Kernel: Abstract Resource Attacks Against OS-level VirtualizationNanzi Yang, Wenbo Shen, Jinku Li, Yutian Yang 等CCS 2021 · 被引用 32 次
- SoK: A Comprehensive Analysis and Evaluation of Docker Container Attack and Defense MechanismsMd. Sadun Haq, Thien Duc Nguyen, Ali Saman Tosun, Franziska Vollmer 等S&P 2024 · 被引用 17 次
- Sync+Sync: A Covert Channel Built on fsync with StorageQisheng Jiang, Chundong WangUSENIX Security 2024 · 被引用 12 次
- Crossing Shifted Moats: Replacing Old Bridges with New Tunnels to Confidential ContainersEnriquillo Valdez, Salman Ahmed, Zhongshu Gu, Christophe de Dinechin 等CCS 2024 · 被引用 4 次
- JANUS: Cross-World, Cooperative Nested Virtualization for Secure ContainersJiangshan Lai, Hang Huang, Quan Xu, Zhen Ren 等OSDI 2026
它引用的顶会 Paper8
- One Bit Flips, One Cloud Flops: Cross-VM Row Hammer Attacks and Privilege EscalationYuan Xiao, Xiaokuan Zhang, Yinqian Zhang, Radu TeodorescuUSENIX Security 2016 · 被引用 272 次
- A Software Approach to Defeating Side Channels in Last-Level CachesZiqiao Zhou, Michael K. Reiter, Yinqian ZhangCCS 2016 · 被引用 155 次
- Security Namespace: Making Linux Security Frameworks Available to ContainersYuqiong Sun, David Safford, Mimi Zohar, Dimitrios Pendarakis 等USENIX Security 2018 · 被引用 79 次
- Covert Channels through Random Number Generator: Mechanisms, Capacity Estimation and MitigationsDmitry Evtyushkin, Dmitry V. PonomarevCCS 2016 · 被引用 75 次
- Exploiting a Thermal Side Channel for Power Attacks in Multi-Tenant Data CentersMohammad A. Islam, Shaolei Ren, Adam WiermanCCS 2017 · 被引用 53 次
相关 Paper
- Losing the Beat: Understanding and Mitigating Desynchronization Risks in Container IsolationZhi Li, Zhen Xu, Weijie Liu, XiaoFeng Wang 等NDSS 2026
- Enjoy the Free Lunch, Someone Paid for Us: Escaping Resource Limits of MicroVM-based ContainersShiwen Wang, Wu Luo, Kaicheng Liu, Zheyuan Xu 等USENIX Security 2026
- Using Trātṛ to tame Adversarial SynchronizationYuvraj Patel, Chenhao Ye, Akshat Sinha, Abigail Matthews 等USENIX Security 2022
- Locks as a Resource: Fairly Scheduling Lock Occupation with CFLJonggyu Park, Young Ik EomPPoPP 2024
- Cross Container Attacks: The Bewildered eBPF on CloudsYi He, Roland Guo, Yunlong Xing, Xijia Che 等USENIX Security 2023
