A Measurement Study on Linux Container Security: Attacks and Countermeasures

A Measurement Study on Linux Container Security: Attacks and Countermeasures
复制标题

DOI:
10.1145/3274694.3274720
复制
发表时间:
2018-12
期刊:
Proceedings of the 34th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Xin Lin;Lingguang Lei;Yuewu Wang;Jiwu Jing;Kun Sun;Quan Zhou
Xin Lin;Lingguang Lei;Yuewu Wang;Jiwu Jing;Kun Sun;Quan Zhou
中科院分区:
其他
文献类型:
--
作者:
Xin Lin;Lingguang Lei;Yuewu Wang;Jiwu Jing;Kun Sun;Quan Zhou

文献摘要

被引文献

相似文献

Linux容器机制备受关注,并越来越多地被用于部署工业应用。尽管由于内核共享特性,容器机制不安全这一点已成为共识,但缺乏利用现实世界中的漏洞对其安全性进行具体且系统的评估。在本文中,我们收集了一个包含223个在容器平台上有效的漏洞的攻击数据集,并使用二维攻击分类法将它们分类到不同类别。然后,我们使用从数据集中筛选出的88个典型漏洞评估现有Linux容器机制的安全性。我们发现,在默认配置下,50个(56.82%)漏洞能够从容器内部成功发起攻击。由于提权漏洞能够完全破坏容器保护机制,我们对这些漏洞进行了深入分析。我们发现诸如能力(Capability)、系统调用过滤器(Seccomp)和强制访问控制(MAC)等内核安全机制在防止提权方面比容器隔离机制(即命名空间(Namespace)和控制组(Cgroup))发挥着更重要的作用。然而,这些内核安全机制之间的相互依存和相互影响关系可能使它们陷入“短板效应”,削弱其保护能力。通过研究仍然能够成功突破容器提供的隔离并实现提权的11个漏洞,我们确定了所有11个漏洞都遵循的一个通用的四步攻击模型。最后,我们提出了一种防御机制,以有效抵御那些已确定的提权攻击。
Linux container mechanism has attracted a lot of attention and is increasingly utilized to deploy industry applications. Though it is a consensus that the container mechanism is not secure due to the kernel-sharing property, it lacks a concrete and systematical evaluation on its security using real world exploits. In this paper, we collect an attack dataset including 223 exploits that are effective on the container platform, and classify them into different categories using a two-dimensional attack taxonomy. Then we evaluate the security of existing Linux container mechanism using 88 typical exploits filtered out from the dataset. We find 50 (56.82%) exploits can successfully launch attacks from inside the container with the default configuration. Since the privilege escalation exploits can completely disable the container protection mechanism, we conduct an in-depth analysis on these exploits. We find the kernel security mechanisms such as Capability, Seccomp, and MAC play a more important role in preventing privilege escalation than the container isolation mechanisms (i.e., Namespace and Cgroup). However, the interdependence and mutual-influence relationship among these kernel security mechanisms may make them fall into the "short board effect" and impair their protection capability. By studying the 11 exploits that still can successfully break the isolation provided by container and achieve privilege escalation, we identify a common 4-step attack model followed by all 11 exploits. Finally, we propose a defense mechanism to effectively defeat those identified privilege escalation attacks.