The vAMP Attack: Taking control of cloud systems via the unified packet parser

Kashyap Thimmaraju, Bhargava Shastry, Tobias Fiebig, Felicitas Hetzelt, Jean Pierre Seifert, Anja Feldmann, Stefan Schmid

Publikation: Bidrag til bog/antologi/rapport/konference proceedingKonferenceartikel i proceedingForskningpeer review

6 Citationer (Scopus)

Abstract

Virtual switches are a crucial component of cloud operating systems that interconnect virtual machines in a flexible manner. They implement complex network protocol parsing in the unified packet parser-parsing all supported packet header fields in a single pass- and are commonly co-located with the virtualization layer. We find that this significantly reduces the barrier for low-budget attackers to launch high impact attacks in the cloud. This leads us to introduce the virtual switch attacker model for packet-parsing, in short the vAMP attack. Using OpenStack, a cloud operating system, and Open vSwitch, a virtual switch, we demonstrate how current virtual switch designs cannot withstand vAMP. Thereby giving a weak attacker full control of the cloud in a matter of minutes.

OriginalsprogEngelsk
TitelCCSW 2017 - Proceedings of the 2017 Cloud Computing Security Workshop, co-located with CCS 2017
Antal sider5
ForlagAssociation for Computing Machinery
Publikationsdato3 nov. 2017
Sider11-15
ISBN (Trykt)978-1-4503-5204-8
ISBN (Elektronisk)9781450353939
DOI
StatusUdgivet - 3 nov. 2017
Begivenhed8th ACM Cloud Computing Security Workshop, CCSW 2017 - Dallas, USA
Varighed: 3 nov. 2017 → …

Konference

Konference8th ACM Cloud Computing Security Workshop, CCSW 2017
Land/OmrådeUSA
ByDallas
Periode03/11/2017 → …
SponsorACM SIGSAC

Fingeraftryk

Dyk ned i forskningsemnerne om 'The vAMP Attack: Taking control of cloud systems via the unified packet parser'. Sammen danner de et unikt fingeraftryk.

Citationsformater