CRII: SaTC: Securing Containers in Multi-Tenant Environment via Augmenting Linux Control Groups
CRII: SaTC: Securing Containers in Multi-Tenant Environment via Augmenting Linux Control Groups
批准号:
2054657
负责人:
Xing Gao
金额:
$15.21万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-08-16 至 2024-05-31
中文摘要
容器技术提供了一个轻量级的操作系统级虚拟主机环境。它被广泛应用于各种计算场景,包括边缘计算、无服务器计算和商业云。容器依赖于Linux内核中的多个构建块来进行资源隔离和控制。特别是,Linux控制组(例如,cgroups)被用来应用资源限制和解释容器的资源使用情况。然而,Linux内核中的这些特性可能无法提供与传统虚拟机相同级别的安全保证。例如,打破cgroups的资源控制不仅会导致多个容器实例之间的资源共享不公平,而且会显著降低容器的性能。该项目旨在通过系统地调查cgroups中的安全影响和开发新的防御系统来保护容器,以减轻多租户容器环境中的潜在安全威胁。该研究预计将识别和解决容器中的新安全挑战,从而使容器服务提供商和客户都受益。教育和推广活动包括系统编程和云安全方面的课程开发,以及为妇女和少数民族学生以及高中生提供研究经验的机会。项目将系统探索打破现有cgroups机制资源控制的方法,全面了解其对Linux容器的安全影响。它开发了一套利用策略来生成带外工作负载以逃避组。开发了一种新的内核代码分析技术,该技术使用数据流、控制流和程序依赖关系图的组合,在启用了一组cgroup资源控制器的情况下,自动发现非特权容器中可用的可行利用案例。在各种攻击场景下的真实容器环境中的多个测试平台上,对所有潜在的漏洞进行了定量评估。具体来说,将评估各种现实世界的工作负载,以了解漏洞的影响和严重性。通过更好地了解现有cgroup机制的不足之处和相关的利用,该项目开发了轻量级防御机制来保护容器并减轻潜在的安全威胁。该系统从性能和安全性等多个方面进行了评估。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Container technology provides a lightweight operating system level virtual hosting environment. It has been broadly adopted in various computation scenarios, including edge computing, serverless computing, and commercial clouds. Containers depend on multiple building blocks in the Linux kernel for resource isolation and control. Particularly, Linux Control Groups (i.e., cgroups) are leveraged to apply resource limits and account for resource usage for containers. However, those features in the Linux kernel may not provide the same level of security guarantees as conventional virtual machines. For example, breaking the resource control of cgroups would not only cause unfair resource sharing among multiple container instances, but also significantly reduce containers’ performance. This project intends to secure containers by systematically investigating security implications in cgroups and developing new defending systems to mitigate potential security threats in multi-tenant container environments. The research is expected to identify and address new security challenges in containers, and thus benefit both container service providers and customers. Educational and outreach activities include curriculum development in systems programming and cloud security, and research experience opportunities for women and minority students as well as for high school students. The project would systematically explore methods to break the resource rein of the existing cgroups mechanism, and comprehensively understand the security impacts on Linux containers. It develops a set of exploiting strategies to generate out-of-band workloads to escape cgroups. Novel kernel code analysis techniques are developed that use a combination of data flow, control flow and program dependency graphs to automatically uncover feasible exploitation cases available inside unprivileged containers with a set of cgroup resource controllers enabled. All potential exploits are quantitatively evaluated on multiple testbeds in realistic container environments under various attack scenarios. Specifically, a variety of real-world workloads are evaluated to understand the impact and severity of vulnerabilities. With better knowledge of the inadequacies in existing cgroup mechanism and related exploitations, the project develops lightweight defense mechanisms to secure containers and mitigate potential security threats. The proposed system is evaluated in terms of multiple aspects including performance and security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Red Alert for Power Leakage: Exploiting Intel RAPL-Induced Side Channels
漏电红色警报:利用 Intel RAPL 引发的侧通道
DOI:
10.1145/3433210.3437517
发表时间:
2021
期刊:
ACM Asia Conference on Computer and Communication Security (Asia CSS ’21
影响因子:
--
作者:
[Zhang, Zhenkai, Liang, Sisheng, Yao, Fan, Gao, Xing]
通讯作者:
Gao, Xing
DOI:
10.1109/dsn53405.2022.00048
发表时间:
2022-06
期刊:
2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
作者:
[Kenton McDonough;Xing Gao;Shuai Wang;Haining Wang]
通讯作者:
Kenton McDonough;Xing Gao;Shuai Wang;Haining Wang
DOI:
10.1145/3442381.3450085
发表时间:
2021-04
期刊:
Proceedings of the Web Conference 2021
影响因子:
--
作者:
[Guannan Liu;Xing Gao;Haining Wang]
通讯作者:
Guannan Liu;Xing Gao;Haining Wang
DOI:
10.1145/3548606.3560647
发表时间:
2022-11
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Guannan Liu;Daiping Liu;Shuai Hao;Xing Gao;Kun Sun;Haining Wang]
通讯作者:
Guannan Liu;Daiping Liu;Shuai Hao;Xing Gao;Kun Sun;Haining Wang
DOI:
10.1109/sp46214.2022.9833595
发表时间:
2022-05
期刊:
2022 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[P. Cronin;Xing Gao;Haining Wang;Chase Cotton]
通讯作者:
P. Cronin;Xing Gao;Haining Wang;Chase Cotton
共 10 条
Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense
-
批准号:2317830
-
项目类别:Continuing Grant
-
资助金额:$30.0万
-
财政年份:2023
-
负责人:Xing Gao
-
依托单位:
CRII: SaTC: Securing Containers in Multi-Tenant Environment via Augmenting Linux Control Groups
-
批准号:1948131
-
项目类别:Standard Grant
-
资助金额:$17.5万
-
财政年份:2020
-
负责人:Xing Gao
-
依托单位:
海外基金