A Misuse Pattern for Compromising VMs via Virtual Machine Escape in NFV

被引:16
作者
Alnaim, Abdulrahman [1 ]
Alwakeel, Ahmed [1 ]
Fernandez, Eduardo B. [1 ]
机构
[1] Florida Atlantic Univ, Dept Comp Sci, Boca Raton, FL 33431 USA
来源
14TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2019) | 2019年
关键词
Cloud computing; Network Function Virtualization (NFV); virtualization; virtual machine environment (VME); hypervisor; misuse patterns; security patterns; SECURITY;
D O I
10.1145/3339252.3340530
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing has provided many services to potential consumers; one of these services being the provision of network functions using virtualization. Network Function Virtualization (NFV) is an emerging network technology that decouples the software implementation of network functions from the underlying hardware providing flexible and energy-efficient network services. However, it also comes with vulnerabilities that attackers can exploit to disrupt the network service. In this paper, we use misuse patterns to study the Virtual Machine (VM) Escape attack. The possible misuses resulting from the VM Escape are compromising victims' VMs, stealing resources from co-resident VMs, and accessing host OS files. Misuse patterns describe how an attack is performed from the point view of the attacker. In the future, we aim to build a partial catalog of misuse patterns for the NFV virtual machine environment (VME). This catalog would be useful to build a Security Reference Architecture for NFV.
引用
收藏
页数:6
相关论文
共 26 条
  • [1] Security in cloud computing: Opportunities and challenges
    Ali, Mazhar
    Khan, Samee U.
    Vasilakos, Athanasios V.
    [J]. INFORMATION SCIENCES, 2015, 305 : 357 - 383
  • [2] Alnaim A.K., 2019, P 13 ANN IEEE INT SY
  • [3] Alnaim A. K., 2019, P 8 AS C PATT LANG P
  • [4] Alnaim A. K., REFERENCE ARCH UNPUB
  • [5] Alwakeel AM, 2018, IEEE SOUTHEASTCON
  • [6] [Anonymous], 2014, 002 NFV GS
  • [7] Buschmann F., 2007, PATTERN ORIENTED SOF, V5, DOI 10.1093/intimm/dxu027
  • [8] Chandramouli R., 2018, NIST SPECIAL PUBLICA, V800-125A
  • [9] Dubrulle P, 2015, IEEE INTL CONF IND I, P1394, DOI 10.1109/INDIN.2015.7281938
  • [10] Fernandez E.B., 2015, Proc. of the 20th European Conference on Pattern Languages of Programs (EuroPLoP '15), P1