Securing self-virtualizing ethernet devices
Igor V. Smolyar, Muli Ben-Yehuda, Dan Tsafrir · 2015
Single root I/O virtualization (SRIOV) is a hard-ware/software interface that allows devices to “self virtu-alize ” and thereby remove the host from the critical I/O path. SRIOV thus brings near bare-metal performance to untrusted guest virtual machines (VMs) in public clouds, enterprise data centers, and high-performance comput-ing setups. We identify a design flaw in current Ethernet SRIOV NIC deployments that enables untrusted VMs to completely control the throughput and latency of other, unrelated VMs. The attack exploits Ethernet ”pause” frames, which enable network flow control functional-ity. We experimentally launch the attack across sev-eral NIC models and find that it is effective and highly accurate, with substantial consequences if left unmiti-gated: (1) to be safe, NIC vendors will have to mod-ify their NICs so as to filter pause frames originating from SRIOV instances; (2) in the meantime, administra-tors will have to either trust their VMs, or configure their switches to ignore pause frames, thus relinquishing flow control, which might severely degrade networking per-formance. We present the Virtualization-Aware Network Flow Controller (VANFC), a software-based SRIOV NIC prototype that overcomes the attack. VANFC filters pause frames from malicious virtual machines without any loss of performance, while keeping SRIOV and Ethernet flow control hardware/software interfaces intact. 1