vArmor:云原生容器安全的多场景应用实践
简介
为什么推出 vArmor
容器运行时组件的默认安全策略存在局限性,无法防御某些漏洞、错误配置风险,也不能限制攻击者在容器内的渗透行为。 构建 AppArmor、Seccomp、SELinux Profile 需要专业知识。 为复杂且快速迭代的容器化应用制定健壮的安全策略(尤其是 Deny-by-Default 模式的策略)难度较大。 AppArmor 或 SELinux LSM 依赖操作系统发行版,存在一定局限性。 在 Kubernetes 环境中,自动化管理和应用不同的安全策略比较复杂。
vArmor 的应用场景
多租户应用的风险
用户接口复杂度较高,接口中的无害 bugs、features 加剧风险 多租户共享组件实现不当。 多租户独占组件安全边界实现不当。
减少用户接口复杂度 将共享组件转变成租户独占组件 提升租户独占组件的隔离性
如何选择加固方案
租户隔离用于弥补由于接口的复杂性而带来的多租户隔离安全风险。而接口复杂度则与漏洞出现概率正相关,下表描述了接口复杂度的简单评估方法 [1]。
还需要做什么
租户负载应满足 Pod Security Standard 的 Baseline 或 Restricted 标准 [2],并使用 NetworkPolicy 等技术实施网络微隔离。 制定合理的调度策略,避免不同租户负载调度到同一个节点。 不同租户使用独占命名空间,以最小权限原则授予租户负载有限的 Kubernetes RBAC 和 IAM 权限,避免授予敏感权限。敏感 RBAC 权限列表可参考 Palo Alto Networks 发布的白皮书 [3]。 制定合理的调度策略,将具有敏感 Kubernetes RBAC 和 IAM 权限的系统组件负载调度到专用节点池,确保租户负载所在节点不存在可被滥用的服务账号和用户账号。 系统组件的敏感接口应开启身份认证和鉴权,避免未授权漏洞。 引入入侵检测系统,在主机、Kubernetes 层面进行入侵检测和防御,及时发现并响应入侵行为。
加固的收益
使用 vArmor 的理由
云原生:遵循 Kubernetes Operator 设计模式,贴近云原生应用开发和运维习惯,从业务视角加固容器化应用,因此易于理解和上手。 灵活性:策略支持多种运行模式(例如 AlwaysAllow、RuntimeDefault、EnhanceProtect 模式),可动态切换且无需重启工作负载。支持拦截、拦截并告警、仅告警不拦截三种特性,有助于策略调试和安全监控。 开箱即用:基于字节跳动在容器安全领域的攻防实践,提供了一系列内置规则,用户可按需在策略对象中选择使用。vArmor 会根据策略对象的配置,生成和管理 Allow-by-Default 模式的 AppArmor、BPF、Seccomp Profile,降低了对专业知识的要求。 易用性:提供了行为建模功能、策略顾问工具,从而辅助策略制定,进一步降低了使用门槛。
常见用法
仅告警不拦截模式(观察模式):将沙箱策略配置为仅告警不拦截模式,通过采集告警日志来分析安全策略对目标应用的影响。
spec:policy:enforcer: BPFmode: EnhanceProtectenhanceProtect:# AuditViolations determines whether to audit the actions that violate the mandatory access control rules. Any detected violation will be logged to /var/log/varmor/violations.log file in the host.# It's disabled by default.auditViolations: true# AllowViolations determines whether to allow the actions that are against the mandatory access control rules.# It's disabled by default.allowViolations: true
spec:policy:enforcer: BPFmode: EnhanceProtectenhanceProtect:# AuditViolations determines whether to audit the actions that violate the mandatory access control rules. Any detected violation will be logged to /var/log/varmor/violations.log file in the host.# It's disabled by default.auditViolations: true
spec:policy:enforcer: BPFmode: EnhanceProtectenhanceProtect:# The custom AppArmor rules:appArmorRawRules:- rules: |audit deny /etc/hosts r,audit deny /etc/shadow r,- rules: "audit deny /etc/hostname r,"targets:- "/bin/bash"# The custom BPF LSM rules:bpfRawRules:processes:- pattern: "**ping"permissions:- execnetwork:egresses:- ip: fdbd:dc01:ff:307:9329:268d:3a27:2ca7- ipBlock: 192.168.1.1/24port: 80sockets:- protocols:- "udp"# The custom Seccomp rules:syscallRawRules:- names:- fchmodataction: SCMP_ACT_ERRNOargs:- index: 2value: 0x40 # S_IXUSRvalueTwo: 0x40op: SCMP_CMP_MASKED_EQ- index: 2value: 0x8 # S_IXGRPvalueTwo: 0x8op: SCMP_CMP_MASKED_EQ- index: 2value: 1 # S_IXOTHvalueTwo: 1op: SCMP_CMP_MASKED_EQ
策略影响排查:当用户怀疑沙箱策略影响目标应用正常执行时,可将策略模式动态切换为 AlwaysAllow、RuntimeDefault 模式排查(注:已启动容器的 Seccomp Profile 不支持动态更新)。
kubectl patch vcpol $POLICY_NAME --type='json' -p='[{"op": "replace", "path": "/spec/policy/mode", "value":"AlwaysAllow"}]'
行为建模模式:使用实验功能 —— 行为建模模式,对目标应用进行建模。建模完成后使用策略顾问来生成沙箱策略模版,辅助沙箱策略的制定。
spec:policy:enforcer: AppArmorSeccompmode: BehaviorModelingmodelingOptions:# The duration in minutes to modelingduration: 30
特权容器的定义
降低特权容器的风险
# mount a new procfsmkdir /tmp/procmount -t proc tmpproc /tmp/procecho "xxx" > /tmp/proc/sys/kernel/core_pattern# bind mount a procfsmount --bind /proc/sys /tmp/procmount -o remount,rw /tmp/proc /tmp/procecho "xxx" > /tmp/proc/sys/kernel/core_pattern
policy:enforcer: BPFmode: EnhanceProtectenhanceProtect:hardeningRules:- disallow-mount-procfs# Privileged is used to identify whether the policy is for the privileged container.# Default is false.privileged: true
辅助特权容器降权
企业生产环境中往往存在许多“特权容器”,虽然大量研究报告和案例都阐明过使用“特权容器”的危害,但企业可能仍然难以对已有的“特权容器”进行降权,也无法按照最小权限原则授予新增容器必要的 capabilities。
spec:policy:enforcer: AppArmorSeccomp# Switching the mode from BehaviorModeling to others is prohibited, and vice versa.# You need recraete the policy to switch the mode from BehaviorModeling to DefenseInDepth.mode: BehaviorModelingmodelingOptions:# The duration in minutes to modelingduration: 30
兼容性说明
AppArmor enforcer 需系统启用 AppArmor LSM BPF enforcer 需 Linux 5.10+ 内核版本支持
原生级性能损耗:依托内核安全子系统,不显著增加上下文切换和数据拷贝开销 无需额外硬件:纯软件实现 无环境绑定:不依赖特定操作系统 零侵入性:保持集群及容器运行时组件的默认配置
总结
引用
PEACH: A Tenant Isolation Framework for Cloud Applications 原文链接:https://www.datocms-assets.com/75231/1671033753-peach_whitepaper_ver1-1.pdf Kubernetes Privilege Escalation: Excessive Permissions in Popular Platforms 原文链接:https://www.paloaltonetworks.com/apps/pan/public/downloadResource?pagePath=/content/pan/en_US/resources/whitepapers/kubernetes-privilege-escalation-excessive-permissions-in-popular-platforms Pod Security Standards 原文链接:https://kubernetes.io/docs/concepts/security/pod-security-standards/ 2024 Data Breach Investigations Report 原文链接:https://www.verizon.com/business/resources/Te3/reports/2024-dbir-data-breach-investigations-report.pdf #BrokenSesame: Accidental ‘write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services 原文链接:https://www.wiz.io/blog/brokensesame-accidental-write-permissions-to-private-registry-allowed-potential-r
相关链接
项目地址: