Enjoy the Free Lunch, Someone Paid for Us: Escaping Resource Limits of MicroVM-based Containers
Shiwen Wang, Wu Luo, Kaicheng Liu, Zheyuan Xu, Yaowen Zheng, Wenhao Wang, Shijun Zhao, Peinan Li, Rui Hou
摘要
MicroVM-based containers are increasingly deployed in public clouds (e.g., AWS, Azure, and Alibaba Cloud) to combine container efficiency with strong isolation. However, we demonstrate that microVM-based architectures introduce a new class of resource accounting vulnerabilities which cause discrepancies between the physical resources consumed by a guest and the resource usage accounted by the host. To systematically uncover such issues, we propose a resource accounting analysis framework that examines accounting inconsistencies across both memory and storage subsystems. Using this framework, we identify three easily exploitable attack vectors: (i) writable memory accounting evasion via shared file-backed mappings, (ii) read-only memory accounting evasion via private file-backed mappings, and (iii) a storage accounting evasion that enables unbounded disk consumption through unmonitored file paths. We further combine these attack vectors into FREE (File-based Resource Expansion & Exploitation), a consolidated attack that freely inflates both memory and storage usage while evading associated resource accounting and billings. We also present a practical attack implementation capable of seamless integration into real-world applications, leveraging a custom dynamic shared library that transparently redirects standard allocations (e.g., malloc) to unaccounted file-backed mappings. We validate the feasibility of the FREE attack on MicroVM-based containers deployed in AWS, Azure and Alibaba Cloud, and use a billing evaluation model to quantify the economic profit of adversarial tenants. Our evaluation demonstrates that FREE can reduce the attacker's billed cost to 42.12% (Kata) and 41.93% (Firecracker) of the original payment. FREE can also be used to degrade the performance of co-located tenants, including up to 57.1% reduction in memory bandwidth and 67.06% loss in I/O throughput.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Houdini's Escape: Breaking the Resource Rein of Linux Control GroupsXing Gao, Zhongshu Gu, Zhengfa Li, Hani Jamjoom 等CCS 2019 · 被引用 62 次
- Demons in the Shared Kernel: Abstract Resource Attacks Against OS-level VirtualizationNanzi Yang, Wenbo Shen, Jinku Li, Yutian Yang 等CCS 2021 · 被引用 32 次
- PVM: Efficient Shadow Paging for Deploying Secure Containers in Cloud-native EnvironmentHang Huang, Jiangshan Lai, Jia Rao, Hui Lu 等SOSP 2023 · 被引用 4 次
- A Hardware-Software Co-Design for Efficient Secure ContainersJiacheng Shi, Yang Yu, Jinyu Gu, Yubin XiaEuroSys 2025
- Attacks are Forwarded: Breaking the Isolation of MicroVM-based Containers Through Operation ForwardingJietao Xiao, Nanzi Yang, Wenbo Shen, Jinku Li 等USENIX Security 2023
相关 Paper
- Firecracker: Lightweight Virtualization for Serverless ApplicationsAlexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori 等NSDI 2020 · 被引用 197 次
- PROBE+DETECT+MITIGATE (PDM): Enabling Cloud Tenants to Self-Defend against Microarchitectural AttacksArash Daneshmand, Hugo Kermabon-Bobinnec, Lingyu Wang, Makan Pourzandi 等USENIX Security 2026
- Exploring and Exploiting the Resource Isolation Attack Surface of WebAssembly ContainersZhaofeng Yu, Dongyang Zhan, Lin Ye, Haining Yu 等USENIX Security 2025
- Demystifying Serverless Costs on Public Platforms: Bridging Billing, Architecture, and OS SchedulingChangyuan Lin, Yuanzhi Ma, Mohammad ShahradEuroSys 2026 · 被引用 3 次
- KASLR in the age of MicroVMsBenjamin Holmes, Jason Waterman, Dan WilliamsEuroSys 2022 · 被引用 5 次
