Evaluation on the Security of Commercial Cloud Container Services

Evaluation on the Security of Commercial Cloud Container Services
复制标题

DOI:
10.1007/978-3-030-62974-8_10
复制
发表时间:
2020
期刊:
--
影响因子:
--
通讯作者:
Yifei Wu;Lingguang Lei;Yuewu Wang;Kun Sun;Jingzi Meng
Yifei Wu;Lingguang Lei;Yuewu Wang;Kun Sun;Jingzi Meng
中科院分区:
其他
文献类型:
--
作者:
Yifei Wu;Lingguang Lei;Yuewu Wang;Kun Sun;Jingzi Meng

文献摘要

相似文献

随着工业界对容器机制的越来越多的采用,云供应商开始提供云容器服务。不幸的是,它缺乏一个具体的方法来评估云容器的安全性,其安全性在很大程度上取决于云提供商实施的安全策略。在本文中,我们首先推导出一个度量检查表,该检查表确定了与云容器服务的安全性相关的关键因素,以应对两种最严重的威胁,即,特权提升和容器逃逸攻击。具体来说,我们确定的指标,直接反映了攻击者的工作条件。我们还通过研究可行的破坏安全措施的方法,包括KASLR、SMEP和SMAP等,提取了实现特权升级和容器逃逸攻击所必需的指标。由于内存损坏漏洞经常被用于特权升级攻击,因此我们收集了公开发布的内存损坏漏洞数据集来辅助评估。然后,我们开发了一个工具,从云容器内部收集清单中列出的度量数据,并对五个在役商业云容器服务进行安全检查。结果表明,一些容器使用弱保护机制(例如,Seccomp机制被禁用),并且KASLR可以在所有五个云容器上被绕过。然而,即使在容器中获得ROOT权限后,攻击者仍然很难从公共云平台上的容器中逃脱,因为容器无法访问为主机操作系统制作或编译内核模块所需的文件。最后,提出了提高云容器服务安全性的建议。
With the increasing adoption of the container mechanism in the industrial community, cloud vendors begin to provide cloud container services. Unfortunately, it lacks a concrete method to evaluate the security of cloud containers, whose security heavily depends on the security policies enforced by the cloud providers. In this paper, we first derive a metric checklist that identifies the critical factors associated with the security of cloud container services against the two most severe threats, i.e., the privilege escalation and container escaping attacks. Specifically, we identify the metrics which directly reflect the working conditions of the attacker. We also extract the metrics essential to achieve privilege escalation and container escaping attacks by investigating the feasible methods for breaking the security measures, including KASLR, SMEP and SMAP, etc. Since memory corruption vulnerabilities are frequently adopted in the privilege escalation attacks, we collect a dataset of the publicly released memory corruption vulnerabilities to assist the evaluation. Then, we develop a tool to collect the metric data listed in the checklist from inside the cloud containers and perform security inspection on five in-service commercial cloud container services. The results show that some containers are enforced with weak protection mechanisms (e.g., with the Seccomp mechanism being disabled), and the KASLR could be bypassed on all five cloud containers. However, even after obtaining ROOT privilege in a container, attackers still can hardly escape from the container on the public cloud platforms, since the necessary files for crafting or compiling a loadable kernel module for the host OS are inaccessible to the container. Finally, we provide some suggestions to improve the security of the cloud container services.