发表机构
National Institute of Technology Calicut(印度国家技术学院卡利卡特分校)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文综述2008至2025年120余篇云安全文献,分析虚拟机逃逸、容器逃逸等威胁,提出ADPO评分框架与1-5级影响量表,并指出安全与性能权衡及低开销检测等开放挑战。
AI 中文摘要
在云计算中,不同用户共享相同的物理硬件,这带来了严重的安全风险。为了保护数据,云系统依赖虚拟机和容器来实现用户隔离。本文回顾了2008年至2025年间发表的120余篇安全文献,重点关注这些隔离边界如何被突破。我们考察了虚拟机逃逸、虚拟机跳转、CPU缓存侧信道、容器逃逸、易受攻击的容器镜像以及分布式拒绝服务(DDoS)攻击等威胁。我们通过三个关键研究问题来评估这些安全威胁及其防御措施。为了比较不同的防御系统,我们引入了一个名为ADPO的定量评分框架,该框架根据准确性、部署便捷性、性能影响和运营开销四个方面,对防御措施进行0至3分的评分。我们还将这些攻击的影响映射到1至5级的严重性量表上,分别针对机密性、完整性和可用性。最后,我们强调了安全与系统性能之间的权衡,并概述了诸如构建低开销入侵检测和创建真实测试数据集等开放挑战。
英文摘要
In cloud computing, different users share the same physical hardware, which creates serious security risks. To protect data, cloud systems rely on virtual machines and containers to keep users isolated. This paper reviews over 120 security publications from 2008 to 2025, focusing on how these isolation boundaries can be breached. We examine threats like virtual machine escape, virtual machine hopping, CPU cache side-channels, container breakouts, vulnerable container images, and distributed denial of service (DDoS) attacks. We evaluate these security threats and their defenses using three key research questions. To compare different defense systems, we introduce a quantitative scoring framework called ADPO, which rates defenses from 0 to 3 based on their Accuracy, Deployment ease, Performance impact, and Operational overhead. We also map the impact of these attacks onto a 1-to-5 severity scale for Confidentiality, Integrity, and Availability. Finally, we highlight the trade-offs between security and system performance, and we outline open challenges like building low-overhead intrusion detection and creating realistic test datasets.