Losing the Beat: Understanding and Mitigating Desynchronization Risks in Container Isolation
Zhi Li, Zhen Xu, Weijie Liu, XiaoFeng Wang, Hai Jin, Zheli Liu
摘要
The isolation offered by containers today is achieved through leveraging Linux namespaces and cgroups in a highly coordinated way. This foundation for container protection, however, has been shaken by the evolution of computing paradigms, particularly the emergence of serverless computing with strong demands for resource sharing across namespaces. Such sharing weakens the container’s isolation model, inducing namespace-cgroup desynchronization (NCD) vulnerabilities, as discovered in our research. In this paper, we present a study on such risks, aiming at identifying their root causes and understanding their implications. Our research reveals that popular container tools all suffer from NCD risks, as evidenced by our discovery of four new vulnerabilities and one bug. Fundamentally, namespace sharing expands a container’s isolation boundary, which may contravene the restrictions set by the cgroups, thereby undermining the combined protection provided by both mechanisms. This contention often cannot be reconciled by existing container tools. To address this challenge and meet the demands for namespace sharing, we propose a kernel-level solution to unify the fragmented responsibilities of namespaces and cgroups in monitoring the resources for container instances. Our design bonds the resource management handled by namespaces with the resource restrictions enforced by cgroups, and identifies the collaborative policies that they should follow. The analysis and evaluation demonstrate that our approach effectively mitigates the NCD risks, as well as incurs a negligible cost to the Linux kernel, mainstream container tools, and real-world applications, maintaining full compatibility with these systems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- Faasm: Lightweight Isolation for Efficient Stateful Serverless ComputingSimon Shillaker, Peter R. PietzuchUSENIX ATC 2020 · 被引用 382 次
- RunD: A Lightweight Secure Container Runtime for High-density Deployment and High-concurrency Startup in Serverless ComputingZijun Li, Jiagan Cheng, Quan Chen, Eryu Guan 等USENIX ATC 2022 · 被引用 106 次
- SPRIGHT: extracting the server from serverless computing! high-performance eBPF-based event-driven, shared-memory processingShixiong Qi, Leslie Monis, Ziteng Zeng, Ian-Chin Wang 等SIGCOMM 2022 · 被引用 85 次
- Security Namespace: Making Linux Security Frameworks Available to ContainersYuqiong Sun, David Safford, Mimi Zohar, Dimitrios Pendarakis 等USENIX Security 2018 · 被引用 79 次
- Houdini's Escape: Breaking the Resource Rein of Linux Control GroupsXing Gao, Zhongshu Gu, Zhengfa Li, Hani Jamjoom 等CCS 2019 · 被引用 62 次
相关 Paper
- Lost along the Way: Understanding and Mitigating Path-Misresolution Threats to Container IsolationZhi Li, Weijie Liu, XiaoFeng Wang, Bin Yuan 等CCS 2023 · 被引用 6 次
- Using Trātṛ to tame Adversarial SynchronizationYuvraj Patel, Chenhao Ye, Akshat Sinha, Abigail Matthews 等USENIX Security 2022
- Demons in the Shared Kernel: Abstract Resource Attacks Against OS-level VirtualizationNanzi Yang, Wenbo Shen, Jinku Li, Yutian Yang 等CCS 2021 · 被引用 32 次
- CLARION: Sound and Clear Provenance Tracking for Microservice DeploymentsXutong Chen, Hassaan Irshad, Yan Chen, Ashish Gehani 等USENIX Security 2021 · 被引用 38 次
- Breaking the Bulkhead: Demystifying Cross-Namespace Reference Vulnerabilities in Kubernetes OperatorsAndong Chen, Ziyi Guo, Zhaoxuan Jin, Zhenyuan Li 等NDSS 2026 · 被引用 2 次
