Torpedo: A Fuzzing Framework for Discovering Adversarial Container Workloads

Torpedo: A Fuzzing Framework for Discovering Adversarial Container Workloads
复制标题

DOI:
10.1109/dsn53405.2022.00048
复制
发表时间:
2022-06
期刊:
2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
Kenton McDonough;Xing Gao;Shuai Wang;Haining Wang
Kenton McDonough;Xing Gao;Shuai Wang;Haining Wang
中科院分区:
其他
文献类型:
--
作者:
Kenton McDonough;Xing Gao;Shuai Wang;Haining Wang

文献摘要

相似文献

容器使计算系统能够托管多个隔离的应用程序,从而更经济高效地使用可用的计算资源。然而,利用共享的计算资源,对手可以发起各种现实世界的攻击(例如,拒绝服务攻击)。在本文中,我们提出了一种基于模糊的方法来检测带外工作负载:这种工作负载可能会在很大程度上干扰同一主机上托管容器实例的性能,从而在系统资源上获得额外的不公平优势,而无需适当收费。TORPEDO改变OS系统调用的输入,同时监控多个容器实例的资源消耗。它使用资源引导的逻辑来找到最大化容器实例和资源限制之间的资源消耗差异的输入。我们在广泛使用的容器化平台上评估了TORPEDO,并证明它可以验证现有研究手动发现的对抗性工作负载。更重要的是,TORPEDO确定了几个不为公众所知的零日漏洞。
Containers enable a computing system to host multiple isolated applications, making more cost-efficient use of the available computing resources. However, exploiting shared computing resources, adversaries can launch various real-world attacks (e.g., denial-of-service attacks) inside containers. In this paper, we present TORPEDO, a fuzzing-based approach to detecting out-of-band workloads: such workloads could largely interfere the performance of colocated container instances on the same host, gaining extra unfair advantages on the system resources without being charged appropriately. TORPEDO mutates inputs of OS syscalls and simultaneously monitors the resource consumption of multiple container instances. It uses resource-guided heuristics to find inputs that maximize the difference in resource consumption between container instances and resource limits. We evaluate TORPEDO on widely-used containerization platforms and demonstrate that it can verify adversarial workloads that are manually discovered by existing research. More importantly, TORPEDO identifies several zero-day vulnerabilities that are not known to the public.