KIT: Testing OS-Level Virtualization for Functional Interference Bugs

KIT: Testing OS-Level Virtualization for Functional Interference Bugs
复制标题

DOI:
10.1145/3575693.3575731
复制
发表时间:
2023-01
期刊:
Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2
影响因子:
--
通讯作者:
Cong Liu;Sishuai Gong;Pedro Fonseca
Cong Liu;Sishuai Gong;Pedro Fonseca
中科院分区:
其他
文献类型:
--
作者:
Cong Liu;Sishuai Gong;Pedro Fonseca

文献摘要

相似文献

容器隔离是通过OS级虚拟化实现的,例如Linux名称空间。不幸的是,这些机制正确实施非常具有挑战性,实际上,这些机制遭受了功能干扰错误的困扰,这会损害容器安全性。特别是,功能干扰错误允许攻击者从同一机器上运行的另一个容器中提取信息,或通过修改错误隔离的内核资源来影响其完整性。尽管它们影响了,但在OS级虚拟化中的功能干扰错误在某种程度上受到了有限的关注,部分原因是检测到它们的挑战。许多功能干扰错误与其引起内存错误或崩溃,涉及难以捕获的逻辑错误,这些错误会静静地产生语义上不正确的结果。本文提出了套件,这是一个动态测试框架,该框架在OS级虚拟化机制(例如Linux名称空间)中发现功能干扰错误。套件的关键思想是通过在两个执行中比较容器的系统调用轨迹来检测范围内功能干扰,并在其上运行和前面执行另一个容器。为了实现高效率和准确性,套件包括两个关键组件:一种有效的算法,用于生成测试用例,以锻炼互操界数据流和系统调用痕迹分析框架,该框架检测功能性干扰错误和集群clusters错误报告。套件在Linux内核5.13中发现了9个功能干扰错误,其中6个已确认。所有错误都是由逻辑错误引起的,表明此方法能够检测到难以捕获的语义错误。
Container isolation is implemented through OS-level virtualization, such as Linux namespaces. Unfortunately, these mechanisms are extremely challenging to implement correctly and, in practice, suffer from functional interference bugs, which compromise container security. In particular, functional interference bugs allow an attacker to extract information from another container running on the same machine or impact its integrity by modifying kernel resources that are incorrectly isolated. Despite their impact, functional interference bugs in OS-level virtualization have received limited attention in part due to the challenges in detecting them. Instead of causing memory errors or crashes, many functional interference bugs involve hard-to-catch logic errors that silently produce semantically incorrect results. This paper proposes KIT, a dynamic testing framework that discovers functional interference bugs in OS-level virtualization mechanisms, such as Linux namespaces. The key idea of KIT is to detect inter-container functional interference by comparing the system call traces of a container across two executions, where it runs with and without the preceding execution of another container. To achieve high efficiency and accuracy, KIT includes two critical components: an efficient algorithm to generate test cases that exercise inter-container data flows and a system call trace analysis framework that detects functional interference bugs and clusters bug reports. KIT discovered 9 functional interference bugs in Linux kernel 5.13, of which 6 have been confirmed. All bugs are caused by logic errors, showing that this approach is able to detect hard-to-catch semantic bugs.