From Hypervisor to Container: Cloud Security Vulnerabilities, Defense Mechanisms, and Open Challenges
cs.CR
Submitted: 2026-09-15
Updated: 2026-09-15
License: http://creativecommons.org/licenses/by/4.0/
The gist: In cloud computing, different users share the same physical hardware, which creates serious security risks.
Terminology
Abstract
In cloud computing, different users share the same physical hardware, which creates serious security risks. To protect data, cloud systems rely on virtual machines and containers to keep users isolated. This paper reviews over 120 security publications from 2008 to 2025, focusing on how these isolation boundaries can be breached. We examine threats like virtual machine escape, virtual machine hopping, CPU cache side-channels, container breakouts, vulnerable container images, and distributed denial of service (DDoS) attacks. We evaluate these security threats and their defenses using three key research questions. To compare different defense systems, we introduce a quantitative scoring framework called ADPO, which rates defenses from 0 to 3 based on their Accuracy, Deployment ease, Performance impact, and Operational overhead. We also map the impact of these attacks onto a 1-to-5 severity scale for Confidentiality, Integrity, and Availability. Finally, we highlight the trade-offs between security and system performance, and we outline open challenges like building low-overhead intrusion detection and creating realistic test datasets.
Sources
- Pouring Cloud Virtualization Security Inside Out
- Escape the Fake: Introducing Simulated Container-Escapes for Honeypots
- Understanding the Quality of Container Security Vulnerability Detection Tools
- Cybersecurity in the AWS Cloud
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs