Locked In, Leaked Out: Measuring Isolation via Kernel Locks

📅 2025-07-28
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
In multi-tenant environments, lock contention on shared kernel data structures—such as filesystem journals and page allocators—is a primary cause of performance interference and isolation failure. This paper proposes the first method to quantitatively assess software-layer isolation by measuring kernel lock contention: leveraging system-level monitoring to precisely track acquisition latency and blocking frequency of diverse kernel locks under concurrent multi-workload execution, thereby establishing a fine-grained isolation analysis framework. Experiments demonstrate that the method accurately identifies isolation bottlenecks across kernel subsystems in virtual machines and containers, revealing filesystem logging and memory management as the dominant sources of interference. Unlike conventional black-box performance profiling, this work pioneers modeling lock-level synchronization behavior as a principled metric for isolation—providing an interpretable, reproducible, and low-level analytical foundation for designing, optimizing, and scheduling resources in multi-tenant systems.

Technology Category

Multiagent Systems: Other Foundations of Multi Agent SystemsMachine Learning: Kernel MethodsData Mining & Knowledge Management: Scalability, Parallel & Distributed Systems

Application Category

Systems and Infrastructure for Web, Mobile and WoT: Web performance, measurement, and characterizationSecurity and Privacy: Large-scale security measurementsWeb Mining and Content Analysis: Web measurements
📝 Abstract
Isolation is a critical property for shared infrastructure to limit exposure and interference among simultaneous running workloads. Cloud providers use different isolation mechanisms such as full Virtual Machines, microVMs, Linux containers, secure containers, etc., to confine workloads running in a multi-tenant environment. We propose a novel way to understand and measure performance interference and isolation at the system software layer that occurs due to shared access to data structures. We observe that interference takes place through shared structures, such as a kernel-level data structure, and that operating systems must synchronize access to these structures for safety. By measuring the level of synchronization between workloads, we can measure their ability to interfere and thus the amount of isolation the platform provides We demonstrate our method for measuring isolation by measuring the accesses to locks acquired in common across multiple workloads which indicates the amount of sharing through kernel data structures and hence the interference/isolation between two workloads. Furthermore, we identify the isolation properties of different kernel structures under different workloads and find that the file system journal and kernel page allocator are the most common sources of interference.
Problem

Research questions and friction points this paper is trying to address.

Measure performance interference via kernel locks
Assess isolation in shared kernel data structures
Identify common sources of workload interference
Innovation

Methods, ideas, or system contributions that make the work stand out.

Measure isolation via kernel lock synchronization
Assess interference through shared kernel structures
Identify common interference sources in workloads
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
A
Anjali
University of Wisconsin-Madison
M
Michael M. Swift
University of Wisconsin-Madison