Aixia Team - Containment Crew
In cooperation with Aixia, we are emulating adversarial container escape techniques in a secure environment. The project runs from late May to early August, with students spending time in Sweden and the United States.
The team:
Emily Blixt - BSc in Global Systems from Chalmers University of Technology, currently pursuing her MSc in Complex Adaptive Systems.
Roch Laferriere - BSc in Computer Science from Dakota State University (DSU), currently pursuing his MSc in Computer Science/AI.
Nicholas Gourley - BSc in Cyber Operations from DSU, currently pursuing his MSc in Cyber Defense.
Marcus Kicklighter - MSc in Engineering: Computer Security at BTH.
Måns Englund - Pursuing a Master of Science in Information and Communication Technology with an emphasis on Software Development from LTH.
Ensuring confidentiality, integrity, and availability of multi-tenant systems are vital for infrastructure as a service (IaaS) companies. This study analyzes practical attack vectors of a multi-tenant, high performance compute cluster. To achieve a nuanced and pragmatic threat model of the target system, a white box penetration test was performed. The goal was to audit the AiQu software provided by Aixia and discover vulnerabilites in the afformentioned software.
A comprehensive mapping of the system was done to gain a further understanding of the target software, its inner workings, and where potential weaknesses might exist. The system breakdown followed a top-down approach. Thereafter, a penetration test was conducted to systematically identify and assess potential security vulnerabilities in the AiQu software. The steps to find vulnerabilities once the system was mapped out were the following:
- Automated security scanning tools
- Enumeration of RESTAPI endpoints
- Enumeration of Linux capabilities in deployed Docker containers
- Fuzzing input fields and REST API fields
- Manual web application testing
- Manual code review
- Read previous security assessments and try variations of previous vulnerabilities
The team will deliver a security assessment report.
Culture & Mindset, Data, Technology, Vision & Strategy
Information Technology
Security
Better Customer Experience, Better Quality, Saving Cost