Matches in SemOpenAlex for { <https://semopenalex.org/work/W2546300025> ?p ?o ?g. }
- W2546300025 abstract "Virtual switches have become popular among cloud operating systems to interconnect virtual machines in a more flexible manner. However, this paper demonstrates that virtual switches introduce new attack surfaces in cloud setups, whose effects can be disastrous. Our analysis shows that these vulnerabilities are caused by: (1) inappropriate security assumptions (privileged virtual switch execution in kernel and user space), (2) the logical centralization of such networks (e.g., OpenStack or SDN), (3) the presence of bi-directional communication channels between data plane systems and the centralized controller, and (4) non-standard protocol parsers. Our work highlights the need to accommodate the data plane(s) in our threat models. In particular, it forces us to revisit today's assumption that the data plane can only be compromised by a sophisticated attacker: we show that compromising the data plane of modern computer networks can actually be performed by a very simple attacker with limited resources only and at low cost (i.e., at the cost of renting a virtual machine in the Cloud). As a case study, we fuzzed only 2% of the code-base of a production quality virtual switch's packet processor (namely OvS), identifying serious vulnerabilities leading to unauthenticated remote code execution. In particular, we present the rein worm which allows us to fully compromise test-setups in less than 100 seconds. We also evaluate the performance overhead of existing mitigations such as ASLR, PIEs, and unconditional stack canaries on OvS. We find that while applying these countermeasures in kernel-space incurs a significant overhead, in user-space the performance overhead is negligible." @default.
- W2546300025 created "2016-11-04" @default.
- W2546300025 creator A5001159554 @default.
- W2546300025 creator A5010174740 @default.
- W2546300025 creator A5027274731 @default.
- W2546300025 creator A5050923169 @default.
- W2546300025 creator A5066080641 @default.
- W2546300025 creator A5067666349 @default.
- W2546300025 creator A5088851494 @default.
- W2546300025 date "2016-10-27" @default.
- W2546300025 modified "2023-09-22" @default.
- W2546300025 title "Reins to the Cloud: Compromising Cloud Systems via the Data Plane" @default.
- W2546300025 cites W1435010830 @default.
- W2546300025 cites W1558403803 @default.
- W2546300025 cites W1608999459 @default.
- W2546300025 cites W1651117873 @default.
- W2546300025 cites W1714884520 @default.
- W2546300025 cites W1863828162 @default.
- W2546300025 cites W1882012874 @default.
- W2546300025 cites W1994926493 @default.
- W2546300025 cites W2022748185 @default.
- W2546300025 cites W2024398916 @default.
- W2546300025 cites W2026309357 @default.
- W2546300025 cites W2047619995 @default.
- W2546300025 cites W2055816813 @default.
- W2546300025 cites W2060172810 @default.
- W2546300025 cites W2071842322 @default.
- W2546300025 cites W2089448621 @default.
- W2546300025 cites W2091144151 @default.
- W2546300025 cites W2101177960 @default.
- W2546300025 cites W2119028650 @default.
- W2546300025 cites W2120881863 @default.
- W2546300025 cites W2123372830 @default.
- W2546300025 cites W2124360577 @default.
- W2546300025 cites W2130531694 @default.
- W2546300025 cites W2135359801 @default.
- W2546300025 cites W2137845741 @default.
- W2546300025 cites W2141077315 @default.
- W2546300025 cites W2142972529 @default.
- W2546300025 cites W2147448476 @default.
- W2546300025 cites W2147802358 @default.
- W2546300025 cites W2149516552 @default.
- W2546300025 cites W2154107289 @default.
- W2546300025 cites W2155624544 @default.
- W2546300025 cites W2155750235 @default.
- W2546300025 cites W2160824842 @default.
- W2546300025 cites W2162618109 @default.
- W2546300025 cites W2286427119 @default.
- W2546300025 cites W2300305891 @default.
- W2546300025 cites W2395731689 @default.
- W2546300025 cites W2753542457 @default.
- W2546300025 hasPublicationYear "2016" @default.
- W2546300025 type Work @default.
- W2546300025 sameAs 2546300025 @default.
- W2546300025 citedByCount "3" @default.
- W2546300025 countsByYear W25463000252017 @default.
- W2546300025 countsByYear W25463000252020 @default.
- W2546300025 crossrefType "posted-content" @default.
- W2546300025 hasAuthorship W2546300025A5001159554 @default.
- W2546300025 hasAuthorship W2546300025A5010174740 @default.
- W2546300025 hasAuthorship W2546300025A5027274731 @default.
- W2546300025 hasAuthorship W2546300025A5050923169 @default.
- W2546300025 hasAuthorship W2546300025A5066080641 @default.
- W2546300025 hasAuthorship W2546300025A5067666349 @default.
- W2546300025 hasAuthorship W2546300025A5088851494 @default.
- W2546300025 hasConcept C10597312 @default.
- W2546300025 hasConcept C111919701 @default.
- W2546300025 hasConcept C120314980 @default.
- W2546300025 hasConcept C158379750 @default.
- W2546300025 hasConcept C25344961 @default.
- W2546300025 hasConcept C2779960059 @default.
- W2546300025 hasConcept C31258907 @default.
- W2546300025 hasConcept C38652104 @default.
- W2546300025 hasConcept C41008148 @default.
- W2546300025 hasConcept C79974875 @default.
- W2546300025 hasConceptScore W2546300025C10597312 @default.
- W2546300025 hasConceptScore W2546300025C111919701 @default.
- W2546300025 hasConceptScore W2546300025C120314980 @default.
- W2546300025 hasConceptScore W2546300025C158379750 @default.
- W2546300025 hasConceptScore W2546300025C25344961 @default.
- W2546300025 hasConceptScore W2546300025C2779960059 @default.
- W2546300025 hasConceptScore W2546300025C31258907 @default.
- W2546300025 hasConceptScore W2546300025C38652104 @default.
- W2546300025 hasConceptScore W2546300025C41008148 @default.
- W2546300025 hasConceptScore W2546300025C79974875 @default.
- W2546300025 hasLocation W25463000251 @default.
- W2546300025 hasOpenAccess W2546300025 @default.
- W2546300025 hasPrimaryLocation W25463000251 @default.
- W2546300025 hasRelatedWork W153121976 @default.
- W2546300025 hasRelatedWork W1535810264 @default.
- W2546300025 hasRelatedWork W2024540116 @default.
- W2546300025 hasRelatedWork W2074943483 @default.
- W2546300025 hasRelatedWork W2130694829 @default.
- W2546300025 hasRelatedWork W2508667123 @default.
- W2546300025 hasRelatedWork W2794064023 @default.
- W2546300025 hasRelatedWork W2803376702 @default.
- W2546300025 hasRelatedWork W2898134739 @default.
- W2546300025 hasRelatedWork W2901383276 @default.
- W2546300025 hasRelatedWork W2901563743 @default.
- W2546300025 hasRelatedWork W2944674008 @default.