YoVDO

Attacks are Forwarded - Breaking the Isolation of MicroVM-based Containers Through Operation Forwarding

Offered By: USENIX via YouTube

Tags

USENIX Security Courses Cybersecurity Courses Cloud Security Courses Attack Surface Analysis Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore a 14-minute conference talk from USENIX Security '23 that reveals a new attack surface for breaking the isolation of microVM-based containers. Discover how researchers identified "operation forwarding attacks" that exploit vulnerabilities in host systems running containerized applications. Learn about the three-layer component structure of microVM-based containers and the corresponding attack strategies for each layer. Examine eight specific attacks demonstrated against Kata Containers and Firecracker-based containers, including their impacts on privilege escalation, IO and CPU performance degradation, and potential host system crashes. Gain insights into experiments conducted in local environments as well as on major cloud platforms like AWS and Alibaba Cloud. Consider the security implications for containerized applications and review suggested mitigation strategies to protect against these newly discovered vulnerabilities.

Syllabus

USENIX Security '23 - Attacks are Forwarded: Breaking the Isolation of MicroVM-based Containers...


Taught by

USENIX

Related Courses

Academia de auditoría en la nube: independencia en la nube (Español LATAM) | Cloud Audit Academy - Cloud Agnostic (Spanish from Latin America)
Amazon Web Services via AWS Skill Builder
Accelerating GKE Incident Response with Prisma Cloud and Cortex XSOAR
Google via Google Cloud Skills Boost
Amazon Detective Deep Dive
A Cloud Guru
AWS Certified Cloud Practitioner (CLF-C01)
A Cloud Guru
AWS Certified Security - Specialty 2020
A Cloud Guru