• DocumentCode
    624298
  • Title

    Breakpoints: An analysis of potential hypervisor attack vectors

  • Author

    Turnbull, Louis ; Shropshire, Jordan

  • Author_Institution
    Allen E. Paulson Coll. of Eng. & Inf. Technol., Georgia Southern Univ., Statesboro, GA, USA
  • fYear
    2013
  • fDate
    4-7 April 2013
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Cloud computing is rapidly transforming the delivery of information services. It offers a scalable, reliable platform to dynamically provision computing resources for geographically distributed users. Despite the benefits of low-cost computing and infrastructure on-demand, the risk of compromised clouds detracts many potential adopters. Cloud services are rendered by virtualized operating systems called virtual machines. Virtual machines reside on specialized servers called hypervisors. Hypervisors provide a conduit to the underlying hardware and resources. Because of their important role, they also represent a prime target for attack. They not only contain virtual machines, but also grant access to hardware resources. The growing number of publicized vulnerabilities indicates that attackers have set their sights on the hypervisor. This research considers vulnerabilities in the ESXi 5.0 hypervisor platform. It focuses on attacks which escalate permissions to exploit host metadata. Four potential attacks vectors are identified and analyzed. Recommendations for coping with these increasing threats are suggested.
  • Keywords
    cloud computing; meta data; operating systems (computers); recommender systems; security of data; virtual machines; ESXi 5.0 hypervisor platform; cloud computing; computing resources; geographically distributed users; hardware resources; hypervisors; information services; metadata; potential adopters; potential hypervisor attack vectors; reliable platform; virtual machines; virtualized operating systems; Hardware; Libraries; Monitoring; Operating systems; Vectors; Virtual machine monitors; Virtual machining; Cloud computing; ESXi 5.0; cloud security; hypervisor; performance monitoring; virtualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Southeastcon, 2013 Proceedings of IEEE
  • Conference_Location
    Jacksonville, FL
  • ISSN
    1091-0050
  • Print_ISBN
    978-1-4799-0052-7
  • Type

    conf

  • DOI
    10.1109/SECON.2013.6567516
  • Filename
    6567516