Evolution of attacks, threat models, and solutions for virtualized systems
File(s)survey_virtualization_final_second.pdf (688.43 KB)
Accepted version
Author(s)
Sgandurra, D
Lupu, E
Type
Journal Article
Abstract
Virtualization technology enables Cloud providers to efficiently use their computing services and resources. Even if the benefits in terms of performance, maintenance, and cost are evident, however, virtualization has also been exploited by attackers to devise new ways to compromise a system. To address these problems, research security solutions have evolved considerably over the years to cope with new attacks and threat models. In this work, we review the protection strategies proposed in the literature and show how some of the solutions have been invalidated by new attacks, or threat models, that were previously not considered. The goal is to show the evolution of the threats, and of the related security and trust assumptions, in virtualized systems that have given rise to complex threat models and the corresponding sophistication of protection strategies to deal with such attacks. We also categorize threat models, security and trust assumptions, and attacks against a virtualized system at the different layers—in particular, hardware, virtualization, OS, and application.
Date Issued
2016-02-08
Date Acceptance
2015-11-30
Citation
ACM Computing Surveys, 2016, 48 (3)
ISSN
1557-7341
Publisher
Association for Computing Machinery (ACM)
Journal / Book Title
ACM Computing Surveys
Volume
48
Issue
3
Copyright Statement
© ACM 2016. This is the author's version of the work. It is posted here for your personal use. Not for redistribution. The definitive Version of Record was published in ACM Computing Surveys, http://dx.doi.org/10.1145/2856126
Sponsor
Commission of the European Communities
Engineering & Physical Science Research Council (EPSRC)
Grant Number
FP7 - 610853
EP/L022729/1
Subjects
Science & Technology
Technology
Computer Science, Theory & Methods
Computer Science
Security
Algorithms
Measurement
Virtualization
threat models
Cloud computing
integrity attacks
MACHINE INTROSPECTION
SECURE
PROTECTION
CLOUD
ARCHITECTURE
HYPERVISOR
INTEGRITY
FUTURE
Information Systems
08 Information And Computing Sciences
Publication Status
Published
Article Number
46