Underwater datacenters (UDCs) hold promise as next-generation data storage due to their energy efficiency and environmental sustainability benefits. While the natural cooling properties of water save power, the isolated aquatic environment and long-range sound propagation in water create unique vulnerabilities which differ from those of on-land data centers. Our research discovers the unique vulnerabilities of fault-tolerant storage devices, resource allocation software, and distributed file systems to acoustic injection attacks in UDCs. With a realistic testbed approximating UDC server operations, we empirically characterize the capabilities of acoustic injection underwater and find that an attacker can reduce fault-tolerant RAID 5 storage system throughput by 17% up to 100%. Our closed-water analyses reveal that attackers can (i) cause unresponsiveness and automatic node removal in a distributed filesystem with only 2.4 minutes of sustained acoustic injection, (ii) induce a distributed database's latency to increase by up to 92.7% to reduce system reliability, and (iii) induce load-balance managers to redirect up to 74% of resources to a target server to cause overload or force resource colocation. Furthermore, we perform open-water experiments in a lake and find that an attacker can cause controlled throughput degradation at a maximum allowable distance of 6.35 m using a commercial speaker. We also investigate and discuss the effectiveness of standard defenses against acoustic injection attacks. Finally, we formulate a novel machine learning-based detection system that reaches 0% False Positive Rate and 98.2% True Positive Rate trained on our dataset of profiled hard disk drives under 30-second FIO benchmark execution. With this work, we aim to help manufacturers proactively protect UDCs against acoustic injection attacks and ensure the security of subsea computing infrastructures.
翻译:水下数据中心因其能效与环境可持续性优势,被视作下一代数据存储的前沿方案。虽然水的自然冷却特性可节省能耗,但孤立的水下环境与声音在水中的远距离传播特性,使水下数据中心面临与陆地数据中心截然不同的独特安全漏洞。本研究发现了容错存储设备、资源分配软件及分布式文件系统在水下数据中心中易受声学注入攻击的独特脆弱性。通过模拟水下数据中心服务器运行的真实测试平台,我们实证刻画了水下声学注入的攻击能力,发现攻击者可使容错RAID 5存储系统的吞吐量降低17%至100%。封闭水域分析表明,攻击者能够:(i) 通过持续2.4分钟的声学注入,导致分布式文件系统无响应并触发节点自动移除;(ii) 使分布式数据库延迟增加高达92.7%,降低系统可靠性;(iii) 诱导负载均衡管理器将74%的资源重定向至目标服务器,引发过载或强制资源共置。进一步在湖泊开展的开放水域实验证实,攻击者可利用商用扬声器在最大容许距离6.35米处实现受控的吞吐量降级。我们同时探究并讨论了标准防御措施对声学注入攻击的有效性。最终,基于30秒FIO基准测试期间采集的硬盘特征数据集,我们构建了一种新型机器学习检测系统,在测试中实现了0%假阳性率与98.2%真阳性率。本研究旨在协助制造商主动防护水下数据中心免受声学注入攻击,保障海底计算基础设施的安全。