ZeroHour
arXiv cs.CRpublished ()ingested Swapnil Vishwas Baviskar

From Hypervisor to Container: Cloud Security Vulnerabilities, Defense Mechanisms, and Open Challenges

infoResearchimportance 32
AI summary · glm-5.3

Survey of 120+ cloud security papers (2008-2025) reviews hypervisor and container isolation attacks, scoring defenses with the ADPO framework and CIA impact scale.

This survey reviews over 120 security publications from 2008 to 2025 on breaches of cloud isolation boundaries via virtual machines and containers. Threats examined include VM escape, VM hopping, CPU cache side-channels, container breakouts, vulnerable container images, and DDoS attacks. The authors introduce ADPO, a 0-3 scoring framework rating defenses on accuracy, deployment ease, performance impact, and operational overhead, plus a 1-5 CIA severity mapping for attack impact.

  • Reviews 120+ security publications from 2008-2025 on hypervisor and container isolation
  • ADPO scores defenses 0-3 on accuracy, deployment, performance, and operational overhead
  • Maps attack impact onto a 1-5 confidentiality, integrity, availability severity scale
  • Covers VM escape, hopping, cache side-channels, container breakouts, vulnerable images, DDoS
Full article162 words · extracted from arxiv.org · click to collapse

In cloud computing, different users share the same physical hardware, which creates serious security risks. To protect data, cloud systems rely on virtual machines and containers to keep users isolated. This paper reviews over 120 security publications from 2008 to 2025, focusing on how these isolation boundaries can be breached. We examine threats like virtual machine escape, virtual machine hopping, CPU cache side-channels, container breakouts, vulnerable container images, and distributed denial of service (DDoS) attacks. We evaluate these security threats and their defenses using three key research questions. To compare different defense systems, we introduce a quantitative scoring framework called ADPO, which rates defenses from 0 to 3 based on their Accuracy, Deployment ease, Performance impact, and Operational overhead. We also map the impact of these attacks onto a 1-to-5 severity scale for Confidentiality, Integrity, and Availability. Finally, we highlight the trade-offs between security and system performance, and we outline open challenges like building low-overhead intrusion detection and creating realistic test datasets.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.16675