Torpedo: A Fuzzing Framework for Discovering Adversarial Container Workloads
Torpedo: A Fuzzing Framework for Discovering Adversarial Container Workloads
复制标题
DOI:
10.1109/dsn53405.2022.00048
复制
发表时间:
2022-06
期刊:
影响因子:
--
通讯作者:
Kenton McDonough;Xing Gao;Shuai Wang;Haining Wang
中科院分区:
文献类型:
--
作者:
Kenton McDonough;Xing Gao;Shuai Wang;Haining Wang
Containers enable a computing system to host multiple isolated applications, making more cost-efficient use of the available computing resources. However, exploiting shared computing resources, adversaries can launch various real-world attacks (e.g., denial-of-service attacks) inside containers. In this paper, we present TORPEDO, a fuzzing-based approach to detecting out-of-band workloads: such workloads could largely interfere the performance of colocated container instances on the same host, gaining extra unfair advantages on the system resources without being charged appropriately. TORPEDO mutates inputs of OS syscalls and simultaneously monitors the resource consumption of multiple container instances. It uses resource-guided heuristics to find inputs that maximize the difference in resource consumption between container instances and resource limits. We evaluate TORPEDO on widely-used containerization platforms and demonstrate that it can verify adversarial workloads that are manually discovered by existing research. More importantly, TORPEDO identifies several zero-day vulnerabilities that are not known to the public.