Container Accessing GPU Device


Description

Detects a container process opening an NVIDIA or AMD GPU or accelerator character device. Opening such a device is required to submit compute work to the hardware, making this a high-signal indicator of GPU cryptojacking when it originates from a workload that is not expected to use accelerators. It complements the network- and process-name-centric cryptominer rules, which a GPU miner can evade by using an unknown binary name and an unknown mining pool. Because a miner cannot submit work to a GPU without opening the device, this device open is a reliable behavioral chokepoint for the Resource Hijacking technique.

Query · falco

open_gpu_device and container and not user_known_gpu_workloads

Rule dependencies

Depends on

  • composes · Falco macro container
    A shared condition, not a detection, so it is not indexed on this site.
  • composes · Falco macro open_gpu_device
    A shared condition, not a detection, so it is not indexed on this site.
  • composes · Falco macro user_known_gpu_workloads
    A shared condition, not a detection, so it is not indexed on this site.

Analyst notes

Container accessing GPU device | device=%fd.name evt_type=%evt.type user=%user.name user_uid=%user.uid user_loginuid=%user.loginuid process=%proc.name proc_exepath=%proc.exepath parent=%proc.pname command=%proc.cmdline terminal=%proc.tty

Raw source Container Accessing GPU Device · Falco YAML
Esc
Published by falcosecurity/rules ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
rule: Container Accessing GPU Device
desc: 'Detects a container process opening an NVIDIA or AMD GPU or accelerator character
  device. Opening such a device is required to submit compute work to the hardware,
  making this a high-signal indicator of GPU cryptojacking when it originates from
  a workload that is not expected to use accelerators. It complements the network-
  and process-name-centric cryptominer rules, which a GPU miner can evade by using
  an unknown binary name and an unknown mining pool. Because a miner cannot submit
  work to a GPU without opening the device, this device open is a reliable behavioral
  chokepoint for the Resource Hijacking technique.

  '
condition: 'open_gpu_device and container and not user_known_gpu_workloads

  '
enabled: false
output: Container accessing GPU device | device=%fd.name evt_type=%evt.type user=%user.name
  user_uid=%user.uid user_loginuid=%user.loginuid process=%proc.name proc_exepath=%proc.exepath
  parent=%proc.pname command=%proc.cmdline terminal=%proc.tty
priority: CRITICAL
tags:
- maturity_sandbox
- container
- filesystem
- mitre_impact
- T1496

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.