Warmonger Attack: A Novel Attack Vector in Serverless Computing

被引:0
|
作者
Xiong, Junjie [1 ]
Wei, Mingkui [2 ]
Lu, Zhuo [3 ]
Liu, Yao [1 ]
机构
[1] Univ S Florida, Dept Comp Sci & Engn, Tampa, FL 33620 USA
[2] George Mason Univ, Dept Cybersecur Engn, Fairfax, VA 22030 USA
[3] Univ S Florida, Dept Elect Engn, Tampa, FL 33620 USA
关键词
IP networks; Codes; Serverless computing; Costs; Vectors; Hardware; Computational modeling; Cloud computing; edge computing; serverless functions; denial-of-service; DEFENSE;
D O I
10.1109/TNET.2024.3437432
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We debut the Warmonger attack, a novel attack vector that can cause denial-of-service between a serverless computing platform and an external content server. The Warmonger attack exploits the fact that a serverless computing platform shares the same set of egress IPs among all serverless functions, which belong to different users, to access an external content server. As a result, a malicious user on this platform can purposefully misbehave and cause these egress IPs to be blocked by the content server, resulting in a platform-wide denial of service. To validate the effectiveness of the Warmonger attack, we conducted extensive experiments over several months, collecting and analyzing the egress IP usage patterns of five prominent serverless service providers (SSPs): Amazon Web Service (AWS) Lambda, Google App Engine, Microsoft Azure Functions, Cloudflare Workers, and Alibaba Function Compute. Additionally, we conducted a thorough evaluation of the attacker's potential actions to compromise an external server and trigger IP blocking. Our findings revealed that certain SSPs employ surprisingly small sets of egress IPs, sometimes as few as four, which are shared among their user base. Furthermore, our research demonstrates that the serverless platform offers ample opportunities for malicious users to engage in well-known disruptive behaviors, ultimately resulting in IP blocking. Our study uncovers a significant security threat within the burgeoning serverless computing platform and sheds light on potential mitigation strategies, such as the detection of malicious serverless functions and the isolation of such entities.
引用
收藏
页码:4826 / 4841
页数:16
相关论文
共 50 条
  • [31] A Survey of DDoS Attack and Defense Technologies in Cloud Computing
    Yue M.
    Wang H.-Y.
    Wu Z.-J.
    Liu L.
    Jisuanji Xuebao/Chinese Journal of Computers, 2020, 43 (12): : 2315 - 2336
  • [32] Study on Detection Algorithm of DDoS Attack for Cloud Computing
    Luo Ya-dong
    2014 Fifth International Conference on Intelligent Systems Design and Engineering Applications (ISDEA), 2014, : 950 - 953
  • [33] BenchFaaS: Benchmarking Serverless Functions in an Edge Computing Network Testbed
    Carpio, Francisco
    Michalke, Marc
    Jukan, Admela
    IEEE NETWORK, 2023, 37 (05): : 81 - 88
  • [34] Function delivery network: Extending serverless computing for heterogeneous platforms
    Jindal, Anshul
    Gerndt, Michael
    Chadha, Mohak
    Podolskiy, Vladimir
    Chen, Pengfei
    SOFTWARE-PRACTICE & EXPERIENCE, 2021, 51 (09) : 1936 - 1963
  • [35] The Deviation Attack: A Novel Denial-of-Service Attack Against IKEv2
    Ninet, Tristan
    Legay, Axel
    Maillard, Romaric
    Traonouez, Louis-Marie
    Zendra, Olivier
    2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019), 2019, : 66 - 74
  • [36] Deviceless Edge Computing: Extending Serverless Computing to the Edge of the Network
    Glikson, Alex
    Nastic, Stefan
    Dustdar, Schahram
    SYSTOR'17: PROCEEDINGS OF THE 10TH ACM INTERNATIONAL SYSTEMS AND STORAGE CONFERENCE, 2017,
  • [37] Serverless Edge Computing-Where We Are and What Lies Ahead
    Raith, Philipp
    Nastic, Stefan
    Dustdar, Schahram
    IEEE INTERNET COMPUTING, 2023, 27 (03) : 50 - 64
  • [38] Serverless data pipeline approaches for IoT data in fog and cloud computing
    Poojara, Shivananda R.
    Dehury, Chinmaya Kumar
    Jakovits, Pelle
    Srirama, Satish Narayana
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 130 : 91 - 105
  • [39] Video Processing with Serverless Computing: A Measurement Study
    Zhang, Miao
    Zhu, Yifei
    Zhang, Cong
    Liu, Jiangchuan
    PROCEEDINGS OF THE 29TH ACM WORKSHOP ON NETWORK AND OPERATING SYSTEMS SUPPORT FOR DIGITAL AUDIO AND VIDEO (NOSSDAV'19), 2019, : 61 - 66
  • [40] Securing Serverless Computing: Challenges, Solutions, and Opportunities
    Li, Xing
    Leng, Xue
    Chen, Yan
    IEEE NETWORK, 2023, 37 (02): : 166 - 173