Attacks are Forwarded: Breaking the Isolation of MicroVM-based Containers Through Operation Forwarding
Jietao Xiao, Nanzi Yang, Wenbo Shen, Jinku Li, Xin Guo, Zhiqiang Dong, Fei Xie, Jianfeng Ma
摘要
People proposed to use virtualization techniques to reinforce the isolation between containers. In the design, each container runs inside a lightweight virtual machine (called microVM). MicroVM-based containers benefit from both the security of microVM and the high efficiency of the container, and thus are widely used on the public cloud. However, in this paper, we demonstrate a new attack surface that can be exploited to break the isolation of the microVM-based container, called operation forwarding attacks. Our key observation is that certain operations of the microVM-based container are forwarded to host system calls and host kernel functions. The attacker can leverage the operation forwarding to exploit the host kernel's vulnerabilities and exhaust host resources. To fully understand the security risk of operation forwarding attacks, we divide the components of the microVM-based container into three layers according to their functionalities and present corresponding attacking strategies to exploit the operation forwarding of each layer. Moreover, we design eight attacks against Kata Containers and Firecracker-based containers and conduct experiments on the local environment, AWS, and Alibaba Cloud. Our results show that the attacker can trigger potential privilege escalation, downgrade 93.4% IO performance and 75.0% CPU performance of the victim container, and even crash the host. We further give security suggestions for mitigating these attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- SoK: A Comprehensive Analysis and Evaluation of Docker Container Attack and Defense MechanismsMd. Sadun Haq, Thien Duc Nguyen, Ali Saman Tosun, Franziska Vollmer 等S&P 2024 · 被引用 17 次
- Fork in the Road: Reflections and Optimizations for Cold Start Latency in Production Serverless SystemsXiaohu Chai, Tianyu Zhou, Keyang Hu, Jianfeng Tan 等OSDI 2025 · 被引用 7 次
- Crossing Shifted Moats: Replacing Old Bridges with New Tunnels to Confidential ContainersEnriquillo Valdez, Salman Ahmed, Zhongshu Gu, Christophe de Dinechin 等CCS 2024 · 被引用 4 次
- Bugs in Pods: Understanding Bugs in Container Runtime SystemsJiongchi Yu, Xiaofei Xie, Cen Zhang, Sen Chen 等ISSTA 2024 · 被引用 3 次
- Unlocking True Elasticity for the Cloud-Native Era with DandelionTom Kuchler, Pinghe Li, Yazhuo Zhang, Lazar Cvetkovic 等SOSP 2025 · 被引用 1 次
它引用的顶会 Paper9
- One Bit Flips, One Cloud Flops: Cross-VM Row Hammer Attacks and Privilege EscalationYuan Xiao, Xiaokuan Zhang, Yinqian Zhang, Radu TeodorescuUSENIX Security 2016 · 被引用 272 次
- Firecracker: Lightweight Virtualization for Serverless ApplicationsAlexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori 等NSDI 2020 · 被引用 197 次
- A Tale of Two Worlds: Assessing the Vulnerability of Enclave Shielding RuntimesJo Van Bulck, David F. Oswald, Eduard Marin, Abdulla Aldoseri 等CCS 2019 · 被引用 159 次
- Nyx: Greybox Hypervisor Fuzzing using Fast Snapshots and Affine TypesSergej Schumilo, Cornelius Aschermann, Ali Abbasi, Simon Wörner 等USENIX Security 2021 · 被引用 102 次
- Security Namespace: Making Linux Security Frameworks Available to ContainersYuqiong Sun, David Safford, Mimi Zohar, Dimitrios Pendarakis 等USENIX Security 2018 · 被引用 79 次
相关 Paper
- Enjoy the Free Lunch, Someone Paid for Us: Escaping Resource Limits of MicroVM-based ContainersShiwen Wang, Wu Luo, Kaicheng Liu, Zheyuan Xu 等USENIX Security 2026
- Cross Container Attacks: The Bewildered eBPF on CloudsYi He, Roland Guo, Yunlong Xing, Xijia Che 等USENIX Security 2023
- SKernel: An Elastic and Efficient Secure Container System at Scale with a Split-Kernel ArchitectureXiaohu Chai, Keyang Hu, Jianfeng Tan, Tiwei Bie 等EuroSys 2026 · 被引用 1 次
- Exploring and Exploiting the Resource Isolation Attack Surface of WebAssembly ContainersZhaofeng Yu, Dongyang Zhan, Lin Ye, Haining Yu 等USENIX Security 2025
- A Hardware-Software Co-Design for Efficient Secure ContainersJiacheng Shi, Yang Yu, Jinyu Gu, Yubin XiaEuroSys 2025
