{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T14:46:12Z","timestamp":1784040372348,"version":"3.55.0"},"reference-count":34,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2021,7,19]],"date-time":"2021-07-19T00:00:00Z","timestamp":1626652800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>With the advent of microservice-based software architectures, an increasing number of modern cloud environments and enterprises use operating system level virtualization, which is often referred to as container infrastructures. Docker Swarm is one of the most popular container orchestration infrastructures, providing high availability and fault tolerance. Occasionally, discovered container escape vulnerabilities allow adversaries to execute code on the host operating system and operate within the cloud infrastructure. We show that Docker Swarm is currently not secured against misbehaving manager nodes. This allows a high impact, high probability privilege escalation attack, which we refer to as leadership hijacking, the possibility of which is neglected by the current cloud security literature. Cloud lateral movement and defense evasion payloads allow an adversary to leverage the Docker Swarm functionality to control each and every host in the underlying cluster. We demonstrate an end-to-end attack, in which an adversary with access to an application running on the cluster achieves full control of the cluster. To reduce the probability of a successful high impact attack, container orchestration infrastructures must reduce the trust level of participating nodes and, in particular, incorporate adversary immune leader election algorithms.<\/jats:p>","DOI":"10.3390\/e23070914","type":"journal-article","created":{"date-parts":[[2021,7,19]],"date-time":"2021-07-19T04:55:40Z","timestamp":1626670540000},"page":"914","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Leadership Hijacking in Docker Swarm and Its Consequences"],"prefix":"10.3390","volume":"23","author":[{"given":"Adi","family":"Farshteindiker","sequence":"first","affiliation":[{"name":"Software and Information Systems Engineering, Ben Gurion University of the Negev, Beer Sheva 8410501, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7229-3899","authenticated-orcid":false,"given":"Rami","family":"Puzis","sequence":"additional","affiliation":[{"name":"Software and Information Systems Engineering, Ben Gurion University of the Negev, Beer Sheva 8410501, Israel"},{"name":"Telekom Innovation Labs, Ben Gurion University of the Negev, Beer Sheva 8410501, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,7,19]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"205","DOI":"10.1007\/s11721-020-00183-1","article-title":"On the robustness of consensus-based behaviors for robot swarms","volume":"14","author":"Moussa","year":"2020","journal-title":"Swarm Intell."},{"key":"ref_2","unstructured":"Ongaro, D., and Ousterhout, J.K. (2014, January 19\u201320). In search of an understandable consensus algorithm. Proceedings of the USENIX Annual Technical Conference, Philadelphia, PA, USA."},{"key":"ref_3","unstructured":"Reuben, J.S. (2007). A survey on virtual machine security. T-110.5290 Seminar on Network Security, Helsinki University of Technology. Available online: https:\/\/citeseerx.ist.psu.edu\/viewdoc\/summary?doi=10.1.1.626.4718."},{"key":"ref_4","unstructured":"Moeller, K.-T. (2007). Virtual Machine Benchmarking. [Ph.D. Thesis, Karlsruhe Institute of Technology]."},{"key":"ref_5","unstructured":"(2021, July 08). Figure, Container vs. vm Arch. Available online: https:\/\/www.docker.com\/resources\/what-container."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1145\/279227.279229","article-title":"The part-time parliament","volume":"16","author":"Lamport","year":"1998","journal-title":"ACM Trans. Comput. Syst. (TOCS)"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Lampson, B.W. (1996). How to build a highly available system using consensus. International Workshop on Distributed Algorithms, Springer.","DOI":"10.1007\/3-540-61769-8_1"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Lamport, L. (2011). Brief Announcement: Leaderless Byzantine Paxos, Springer.","DOI":"10.1007\/978-3-642-24100-0_10"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"398","DOI":"10.1145\/571637.571640","article-title":"Practical byzantine fault tolerance and proactive recovery","volume":"20","author":"Castro","year":"2002","journal-title":"ACM Trans. Comput. Syst. (TOCS)"},{"key":"ref_10","unstructured":"Castro, M., and Liskov, B. (1999, January 22\u201325). Practical byzantine fault tolerance. Proceedings of the Third Symposium on Operating Systems Design and Implementation, New Orleans, LA, USA."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Bessani, A., Sousa, J.A., and Alchieri, E.E.P. (2014, January 23\u201326). State machine replication for the masses with bft-smart. Proceedings of the 2014 44th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, Atlanta, GA, USA.","DOI":"10.1109\/DSN.2014.43"},{"key":"ref_12","first-page":"321","article-title":"Overview of attacks on cloud computing","volume":"1","author":"Singh","year":"2012","journal-title":"Int. J. Eng. Innov. Technol. (IJEIT)"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Jensen, M., Gruschka, N., and Luttenberger, N. (2008, January 4\u20137). The impact of flooding attacks on network-based services. Proceedings of the 2008 Third International Conference on Availability, Reliability and Security, Barcelona, Spain.","DOI":"10.1109\/ARES.2008.16"},{"key":"ref_14","unstructured":"Darwish, M., Ouda, A., and Capretz, L.F. (2013, January 24\u201326). Cloud-based ddos attacks and defenses. Proceedings of the International Conference on Information Society (i-Society 2013), Toronto, ON, Canada."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Gruss, D., Maurice, C., Wagner, K., and Mangard, S. (2016). Flush+ flush: A fast and stealthy cache attack. International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, Springer.","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"ref_16","unstructured":"Yarom, Y., and Falkner, K. (2021, July 08). Flush+ Reload: A High Resolution, Low Noise, l3 Cache Side-Channel Attack. Available online: https:\/\/www.usenix.org\/node\/184416."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Liu, F., Yarom, Y., Ge, Q., Heiser, G., and Lee, R.B. (2015, January 17\u201321). Last-level cache side-channel attacks are practical. Proceedings of the 2015 IEEE Symposium on Security and Privacy, San Jose, CA, USA.","DOI":"10.1109\/SP.2015.43"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Wei\u00df, M., Heinz, B., and Stumpf, F. (2012). A cache timing attack on aes in virtualization environments. International Conference on Financial Cryptography and Data Security, Springer.","DOI":"10.1007\/978-3-642-32946-3_23"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Jensen, M., Schwenk, J., Gruschka, N., and Iacono, L.L. (2009, January 21\u201325). On technical security issues in cloud computing. Proceedings of the 2009 IEEE International Conference on Cloud Computing, Bangalore, India.","DOI":"10.1109\/CLOUD.2009.60"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Liu, D., and Zhao, L. (2014, January 19\u201321). The research and implementation of cloud computing platform based on docker. Proceedings of the 2014 11th International Computer Conference on Wavelet Actiev Media Technology and Information Processing (ICCWAMTIP), Chengdu, China.","DOI":"10.1109\/ICCWAMTIP.2014.7073453"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Marathe, N., Gandhi, A., and Shah, J. (2019, January 23\u201325). Docker Swarm and kubernetes in cloud computing environment. Proceedings of the 2019 3rd International Conference On Trends In Electronics And Informatics (ICOEI), Tirunelveli, India.","DOI":"10.1109\/ICOEI.2019.8862654"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Xavier, M.G., Neves, M.V., Rossi, F.D., Ferreto, T.C., Lange, T., and De Rose, C.A.F. (March, January 27). Performance evaluation of container-based virtualization for high performance computing environments. Proceedings of the 2013 21st Euromicro International Conference on Parallel, Distributed, and Network-Based Processing, Belfast, UK.","DOI":"10.1109\/PDP.2013.41"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Wu, Y., Lei, L., Wang, Y., Sun, K., and Meng, J. (2020). Evaluation on the Security of Commercial Cloud Container Services. International Conference on Information Security, Springer.","DOI":"10.1007\/978-3-030-62974-8_10"},{"key":"ref_24","unstructured":"Linetskyi, A., Babenko, T., Myrutenko, L., and Vialkova, V. (2020). Eliminating privilage escalation to root in containers running on kubernetes. Sci. Pract. Cyber Secur. J., Available online: https:\/\/journal.scsa.ge\/papers\/eliminating-privilage-escalation-to-root-in-containers-running-on-kubernetes\/."},{"key":"ref_25","unstructured":"S\u00e6ther, D. (2018). Security in Docker Swarm: Orchestration Service for Distributed Software Systems. [Master\u2019s Thesis, The University of Bergen]."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Amara, N., Zhiqui, H., and Ali, A. (2017, January 12\u201314). Cloud computing security threats and attacks with their mitigation techniques. Proceedings of the 2017 International Conference On Cyber-Enabled Distributed Computing And Knowledge Discovery (CyberC), Nanjing, China.","DOI":"10.1109\/CyberC.2017.37"},{"key":"ref_27","unstructured":"Kabbe, J.A. (2017). Security Analysis of Docker Containers in a Production Environment. [Master\u2019s Thesis, NTNU]."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1109\/MCC.2016.100","article-title":"To docker or not to docker: A security perspective","volume":"3","author":"Combe","year":"2016","journal-title":"IEEE Cloud Comput."},{"key":"ref_29","unstructured":"(2021, July 08). Docker Node Demote Api. Available online: https:\/\/docs.docker.com\/engine\/reference\/commandline\/node_demote\/."},{"key":"ref_30","unstructured":"(2021, July 08). Docker Node Promote Api. Available online: https:\/\/docs.docker.com\/engine\/reference\/commandline\/node_promote\/."},{"key":"ref_31","unstructured":"Choumas, K., and Korakis, T. (July, January 29). When Raft Meets SDN: How to Elect a Leader over a Network. Proceedings of the 6th IEEE Conference on Network Softwarization (NetSoft), Ghent, Belgium."},{"key":"ref_32","unstructured":"Kennedy, D., O\u2019gorman, J., Kearns, D., and Aharoni, M. (2011). Metasploit: The Penetration Tester\u2019s Guide, No Starch Press."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1109\/TC.2011.221","article-title":"Efficient byzantine fault-tolerance","volume":"62","author":"Veronese","year":"2011","journal-title":"IEEE Trans. Comput."},{"key":"ref_34","unstructured":"Cowling, J., Myers, D., Liskov, B., Rodrigues, R., and Shrira, L. (2006, January 6\u20138). Hq replication: A hybrid quorum protocol for byzantine fault tolerance. Proceedings of the 7th Symposium on Operating Systems Design and Implementation, Seattle, WA, USA."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/23\/7\/914\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T06:31:38Z","timestamp":1760164298000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/23\/7\/914"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,19]]},"references-count":34,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2021,7]]}},"alternative-id":["e23070914"],"URL":"https:\/\/doi.org\/10.3390\/e23070914","relation":{"has-preprint":[{"id-type":"doi","id":"10.20944\/preprints202105.0594.v1","asserted-by":"object"}]},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,7,19]]}}}