开发者社区> 问答> 正文

A security issue can make a DoS attack in the ASM.

We find a docker security issue to exhaust all struct files in Linux Kernel and causing a DoS attack in the Alibaba ASM environment.

Reproduction steps:

  1. Follow the ASM tutorial to set up ASM clusters. We use two Virtual Machine with 16G memory, 120G ESSD Disk, CentOS 7.7 OS, Kubernetes Version V1.18.8-aliyun.1, and Docker Version 19.3.5, to set the Alibaba Kubernetes Cluster. All those settings are done through Alibaba ASM UI.
  2. Deploy the docker unprivileged malicious container with UID 1000, dropping all capabilities, using limited memory 4G, running on special core, and disable privilege escalation. We run the malicious container in a separate Kubernetes Namespace.
  3. Inside the malicious container, we repeatedly make the timerfd_create/open syscalls. In the malicious container, we start 2100 processes, each process with a 1024 max number of open files, which is the default ulimit value. In total, around 2097152 number struct-file are consumed and there is no available struct-file in the kernel. As a result, the victim container can't create any new files. The total consumed memory of the malicious container is less than 4G, which is small, so the memory control group cannot help.

Is there any way to defend against this attack inside the Alibaba ASM environment? Looking forward to your reply!

展开
收起
游客y22wf6xkdpy2s 2021-04-20 20:18:57 375 0
0 条回答
写回答
取消 提交回答
问答排行榜
最热
最新

相关电子书

更多
Offensive-Malware-Analysis-Dissecting-OSXFruitFly-Via-A-Custom-C&C-Server 立即下载
Taking-Windows-10-Kernel-Exploitation-To-The-Next-Level–Leveraging-Write-What-Where-Vulnerabilities-In-Creators-Update 立即下载
Distributed-Frontend-Arch--Ahmad Amireh 立即下载