Conceptio › Archive › arXiv CS
arXiv CSopen access

From Hypervisor to Container: Cloud Security Vulnerabilities, Defense Mechanisms, and Open Challenges

· arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

From Hypervisor to Container: Cloud Security Vulnerabilities, Defense Mechanisms, and Open Challenges Swapnil Vishwas Baviskara , Sanoj Ra and Hiran V Natha

arXiv:2609.16675v1 [cs.CR] 15 Sep 2026

a National Institute of Technology Calicut, Computer Science and Engineering Department, Kozhikode, 673601, Kerala, India

ARTICLE INFO

ABSTRACT

Keywords: Virtualization VM Escape VM Hopping container security Vulnerable container image distributed denial of service (DDoS) attacks

In cloud computing, different users share the same physical hardware, which creates serious security risks. To protect data, cloud systems rely on virtual machines and containers to keep users isolated. This paper reviews over 120 security publications from 2008 to 2025, focusing on how these isolation boundaries can be breached. We examine threats like virtual machine escape, virtual machine hopping, CPU cache side-channels, container breakouts, vulnerable container images, and distributed denial of service (DDoS) attacks. We evaluate these security threats and their defenses using three key research questions. To compare different defense systems, we introduce a quantitative scoring framework called ADPO, which rates defenses from 0 to 3 based on their Accuracy, Deployment ease, Performance impact, and Operational overhead. We also map the impact of these attacks onto a 1-to-5 severity scale for Confidentiality, Integrity, and Availability. Finally, we highlight the trade-offs between security and system performance, and we outline open challenges like building low-overhead intrusion detection and creating realistic test datasets.

1. Introduction Cloud computing lets many different users share the same physical computers. To keep these users isolated, cloud platforms rely on virtual machines (VMs) and containers. At the hardware level, a hypervisor controls access to CPUs, memory, and storage [1]. Higher up at the operating system level, container engines offer a lighter way to run applications. Sharing physical hardware makes cloud computing highly efficient, but it also creates security risks. If two users share a CPU cache, one might spy on the other. If a guest VM escapes, the whole physical server could be compromised. Most security papers look at these risks as isolated software bugs. In this paper, we take a broader look. We view cloud security as a balance between safety controls and system speed. We analyze how cloud defense mechanisms actively respond to attacks and how they affect CPU, memory, and storage performance. To see how our work compares to existing literature, Table 1 maps out recent cloud security surveys. Our survey stands out by using a quantitative scoring system to compare defenses rather than just listing their features. We guide this review using three main research questions: • RQ1 (Threat Architecture): What are the fundamental differences in the attack surfaces of hypervisorlevel virtual machines and OS-level containers? • RQ2 (Defense Trade-offs): How well do current cloud defenses adapt to new attacks, and what are their performance and operational trade-offs under our ADPO scoring system? [email protected] (S.V. Baviskar); [email protected] (S. R); [email protected] (H.V. Nath) ORCID (s): 0000-0001-7881-4694 (H.V. Nath)

• RQ3 (Impact on CIA): How do cloud exploits affect Confidentiality, Integrity, and Availability, and how can we measure these risks quantitatively? Specifically, this paper provides the following: • Systems-Based Analysis: We analyze cloud security as a set of interacting parts, showing how defenses balance threat protection against resource overhead. • PRISMA Literature Review: We select and review over 120 papers published between 2008 and 2025 using a clear, multi-stage screening process. • ADPO Scoring Framework: We score defense mechanisms from 0 to 3 based on four areas: Detection Accuracy, Deployment Ease, Performance Impact, and Storage/Memory Overhead. This replaces simple descriptive comparisons with clear data. • CIA Triad Risk Matrix: We create a 1-to-5 scoring system to measure how severely different attacks affect Confidentiality, Integrity, and Availability. We also outline the main challenges for future cloud security research.

2. Methodology We used the PRISMA guidelines (Preferred Reporting Items for Systematic Reviews and Meta-Analyses) to design and run our literature search. We searched six main academic databases for papers published between 2008 and 2025: IEEE Xplore, ACM Digital Library, Google Scholar, Scopus, ScienceDirect, and SpringerLink. Our search string was: (“VM escape” OR “VM hopping” OR “cache side-channel” OR “container breakout” OR “container image vulnerability” OR “DDoS cloud”) AND (“hypervisor” OR “virtualization” OR “cloud security” OR “intrusion detection”).

We selected papers using three steps:

Swapnil Baviskar et al.: Preprint submitted to Elsevier

Page 1 of 19

From Hypervisor to Container: A Survey of Cloud Security Table 1 Comparative Analysis of Cloud Security Surveys against the Proposed Work Survey Reference Alharthi et al. [2]

VM Security ✓

Container Security ×

Cache SCA ×

DDoS Infrastructure ×

Scored Model ×

Sultan et al. [3]

×

✓

×

×

×

Guo et al. [4]

×

×

✓

×

×

Lal et al. [2]

✓

✓

×

✓

×

Proposed Work

✓

✓

✓

✓

✓

1. Identification: We ran our search query and found 𝑁1 = 512 papers. 2. Screening: We removed duplicates and read the titles and abstracts. We removed papers that did not fit our security focus, leaving 𝑁2 = 284 papers. 3. Inclusion: We read the full text of the remaining papers. We only kept a paper if it: (i) focused on cloud computing (IaaS, PaaS, or SaaS); (ii) tested its ideas with real workloads or experiments; and (iii) directly addressed multi-tenant security or resource isolation. In the end, we kept 𝑁3 = 118 papers for our survey. To compare these papers fairly, we created two new scoring methods: • ADPO Scoring System: We score each defense mechanism from 0 to 3 in four key areas: Detection Accuracy (A), Deployment Ease (D), Performance Preservation (P), and Operational/Storage Overhead (O). A score of 3 is the best (for example, a tool that does not need host agents, has no CPU impact, or catches all attacks). A score of 0 means the tool has severe performance issues or requires special hardware that is hard to get. • CIA Triad Severity Matrix: We rate how badly each type of attack hurts Confidentiality, Integrity, and Availability using a scale from 1 (lowest impact) to 5 (highest impact). This gives a clear, numerical view of risk.

3. Literature Survey 3.1. VM Escape VM escape attacks exploit vulnerabilities in the Virtual Machine Monitor (VMM), or hypervisor, to breach the isolation boundary between a guest VM and the host system [5]. In such an attack, a program executing within a VM bypasses the VMM layer to gain direct access to the host operating system, effectively elevating itself to root-level privileges and compromising the entire security perimeter of the virtualized environment [1]. Three principal escape variants have been identified in the literature: Guest-toVMM, Guest-to-Host, and Guest-to-Guest, with real-world instances including heap-based buffer overflows in QEMU’s Cirrus VGA extension and NE2000 network interface card emulation [6]. As the hypervisor represents a single point of Swapnil Baviskar et al.: Preprint submitted to Elsevier

Primary Perspective & Focus Qualitative hypervisor vulnerability catalog. Pure container security threats and runtime defenses. Microarchitectural sidechannels in virtual systems. Qualitative multi-tenant threat categorization. Systems-centric ADPO scored framework.

failure, a successful escape can cascade across all co-resident VMs, making this the most severe threat in multi-tenant cloud deployments [7, 8]. Privilege escalation via returnoriented programming (ROP) and exploitation of guest OS weaknesses further amplify this risk across both public and private cloud models [9, 2]. Three main ideas have shaped defense systems against virtual machine escape: proactive vulnerability identification, runtime anomaly detection, and preventive architecture and access control. Each paradigm includes essentially different trade-offs between detection accuracy, deployment complexity, and performance overhead and represents a unique feedback-control philosophy, such as reactive monitoring, offline testing, or structural prevention.

3.1.1. Runtime Anomaly Detection (IDS-Based Defenses) Intrusion Detection Systems (IDS), which track hypervisor and virtual machine (VM) behavior in real time and create a closed-loop feedback mechanism to identify and react to escape attempts, are used in the prevalent adaptive defensive paradigm. Within this paradigm, three architectural variations have surfaced. Host-and-guest cooperative IDS: The Virtual Machines and Hypervisor IDS (VMHIDS) deploys monitoring agents on both the hypervisor and all resident VMs, using realtime event analysis to detect anomalous file access, process communication, and network traffic [10]. A game-theoretic extension models the interdependent security decisions of co-resident tenants, demonstrating that Nash equilibriumbased VM allocation can reduce negative externalities from shared platform risks [11]. While VMHIDS provides comprehensive coverage, its requirement for agent deployment on every VM limits scalability. Statistical and ML-based outlier detection: To improve detection stability for low-frequency attacks, the Neighbourhood Outlier Factor (NOF) approach addresses weaknesses in neural network-based IDS by computing reachability distances and local density to determine outlier degrees, achieving reliable classification across diverse attack types [12]. For network-level classification, distance-based clustering methods have achieved 99.761% accuracy across five traffic classes (normal, probing, DoS, R2L, U2R), though R2L and U2R attacks remain difficult to distinguish from normal traffic due to their similarity in processed feature spaces Page 2 of 19

From Hypervisor to Container: A Survey of Cloud Security

[13]. More recently, federated learning-based adaptive protocols have achieved 92.6% detection accuracy—compared to 85.2% for centralised and 78.4% for static approaches— while reducing performance overhead by 55% and training time by 32% through decentralised model synchronisation [14]. Cross-layer correlation and monitoring: Complementing point-detection systems, Security Information and Event Management (SIEM) tools enable cross-layer correlation of hypervisor events, particularly in multi-tenant IaaS environments where resource sharing and elasticity mechanisms introduce additional attack surfaces [15]. Cloud-specific Security Operations Centres (SOCs), such as an OpenStacktailored implementation, normalise platform alerts and apply correlation rules to generate meta-alerts, demonstrating the importance of specialised monitoring architectures for cloud environments [16]. The Trinetra algorithm specifically targets cross-VM time-driven attacks (TDA) with minimal performance overhead by embedding detection logic directly into the host kernel, making it resistant to tampering [17]. Virtual Machine Introspection (VMI): At the hypervisor layer, VMI enables external monitoring of VM memory and process states without requiring in-guest agents. An analysis of 185 vulnerability reports reveals that 86.5% of IaaS cloud attacks originate from within VMs, while inter-VM attacks remain comparatively understudied, suggesting that VMI monitoring should prioritise outbound threat detection [18]. Multi-level monitoring architectures further improve coverage by deploying VM Security Event Monitors (VSEMs) that escalate alerts to host-level managers in a two-stage process [19].

3.1.2. Proactive Vulnerability Discovery Rather than reacting to attacks at runtime, a second paradigm seeks to identify and eliminate VM escape vulnerabilities before deployment through automated testing and formal analysis. Semantics-aware fuzzing: V-SHUTTLE is the first framework to incorporate protocol-level semantics awareness for hypervisor fuzzing, automatically deconstructing hierarchical device structures to target complex code paths [20]. Applied to QEMU and VirtualBox, V-SHUTTLE identified 35 previously unknown vulnerabilities and received 17 CVE assignments, demonstrating the effectiveness of semantics-guided test generation over random fuzzing. Its open-source release further enables reproducible security research. Complementing this, symbolic execution-based frameworks categorise virtualization vulnerabilities into virtual hardware logic errors, device state management errors, and resource availability errors, enabling targeted security testing of virtual hardware without significant source code modifications [21]. Formal modeling: Finite state machine (FSM)-based attack models provide a systematic approach to identifying VM escape vulnerabilities during the design and implementation phases. By extracting privilege models from various virtualization platforms and encoding vulnerability Swapnil Baviskar et al.: Preprint submitted to Elsevier

exploit conditions in Datalog, researchers have identified four distinct attack types from NVD vulnerability reports, enabling early-stage security validation [22]. Misuse pattern catalogues extend this formal approach to Network Function Virtualisation (NFV) environments, creating reusable security reference architectures that help designers understand and defend against escape patterns throughout the hypervisor lifecycle [23].

3.1.3. Preventive Architecture and Access Control The third paradigm eliminates VM escape vectors through structural prevention rather than detection, trading deployment flexibility for stronger security guarantees. Access control models: The PVME model adapts the Bell-LaPadula (BLP) access control framework to virtualized environments, formalising system states and transitions to prevent unauthorised hypervisor communication with minimal time overhead [24]. Role-based access control (RBAC) mechanisms provide adaptive, multi-tenant protection that can enforce diverse security policies beyond simple access restrictions [25]. Hardware-assisted isolation: Hardware-based approaches ensure memory separation independently of the software hypervisor, providing stronger guarantees even when the VMM is compromised. A prototype implementation using System Management Mode (SMM) demonstrates the feasibility of this architecture, though SMM’s design constraints limit both performance and the scope of protection [26]. Optimisation-driven defense: Enhanced Particle Swarm Optimisation (EPSO) combined with the HADAES algorithm jointly optimises resource allocation and hypervisor attack detection, achieving improved reliability, throughput, and energy consumption compared to conventional approaches [27]. Defense-in-depth architectures, such as Cloud-Trust, provide layered security evaluation models that assess confidentiality and integrity across multiple control levels, demonstrating that comprehensive defense strategies significantly reduce the risk of advanced persistent threats (APTs) exploiting VM escape vectors [28]. 3.1.4. Cross-Paradigm Comparative Discussion Comparing these three paradigms reveals a fundamental trade-off between adaptability and assurance strength. Runtime IDS approaches [10, 12, 17, 14] function as adaptive feedback systems that can respond to novel threats but suffer from false positives and continuous resource overhead. Proactive discovery methods [20, 21, 22] provide strong predeployment assurance but operate offline and cannot protect against zero-day attacks that emerge post-deployment. Preventive architectures [24, 26] offer the strongest isolation guarantees but demand significant architectural changes and hardware dependencies that limit adoption in heterogeneous cloud environments. The literature further reveals that the majority of existing defense solutions prioritise integrity and confidentiality, while availability-focused defenses remain scarce [29]. VM hardening techniques, including hypervisor patching and Page 3 of 19

From Hypervisor to Container: A Survey of Cloud Security Table 2 System-Level Evaluation of VM Escape Defenses under the ADPO Maturity Framework Mechanism & Citation VMHIDS [10]

A 1

D 0

P 2

O 1

Primary System Control Cooperating in-guest and hypervisor audit agents

V-SHUTTLE [20]

3

2

3

3

Semantics-aware offline device fuzzer

PVME [24] Hardware Separation [26]

2 3

1 0

3 2

3 3

VMM Bell-LaPadula access control rules SMM-based CPU register & memory isolation

EPSO + HADAES [27]

2

1

3

2

Heuristic scheduling resource optimizer

FL Adaptive Protocol [14]

2

1

3

2

Decentralized federated anomaly modeling

configuration management, complement all three paradigms but introduce their own resource overhead [30, 31]. Critically, the threat landscape differs across deployment models: public clouds face greater external exposure, while private clouds are more susceptible to insider threats [2, 32]. A comprehensive defense strategy must therefore integrate elements from all three paradigms, combining real-time anomaly detection with proactive vulnerability assessment and structural isolation to provide layered, deploymentaware protection. A quantitative comparison of representative defense mechanisms across the four evaluation dimensions is presented in Table 2.

3.2. VM Hopping VM hopping—sometimes called guest jumping—exploits weaknesses in the virtualization layer to let an attacker pivot laterally from one guest VM to another on the same physical host [33]. The attacker typically compromises a low-security VM first, then uses it as a springboard to reach co-resident targets, gaining access to their configurations, stored data, and resource management interfaces. What makes this threat particularly damaging in cloud settings is the multi-tenant model itself: because several VMs share a single server, one successful hop can put every tenant on that host at risk [34]. The impact ripples upward through the service stack. SaaS providers that lease infrastructure from PaaS or IaaS vendors inherit the vulnerability indirectly—if the underlying VMs are susceptible to hopping, both availability and data integrity of the SaaS layer are jeopardised [34]. A recent practitioner survey underscores how underestimated this threat remains: only 3.2% of respondents identified VM hopping as a recognised attack vector [35]. Broader cloud security frameworks have also flagged the absence of a coherent, generalised treatment of VM hopping defenses across the literature [36]. Defense mechanisms against VM hopping fall into two broad categories: those that try to detect lateral movement after it begins, and those that try to prevent co-residency or block inter-VM communication channels before an attack can occur.

3.2.1. Detection-Based Defenses Detection-oriented approaches treat VM hopping as a runtime anomaly that can be caught through careful monitoring of inter-VM traffic and behaviour. Swapnil Baviskar et al.: Preprint submitted to Elsevier

Key Quantitative Metric / Guarantee Game-theoretic Nash equilibrium for safety allocation Identified 35 zero-day vulnerabilities (17 CVEs) in QEMU/VBox Formal proof of safe virtualization transitions Hardware-enforced isolation independent of VMM state Dynamic threat mitigation with optimal energy scheduling 92.6% accuracy, 55% overhead reduction vs. centralized ML

Evidence-fusion IDS: One of the earlier cloud-specific IDS designs [33] analyses data flow patterns between neighbouring VMs rather than relying solely on external network traffic. The key idea is that internal VM interactions carry richer signals about lateral movement than perimeter-based analysis. A two-level evidence fusion scheme [37] built on Dempster-Shafer theory extends this line of work. The system treats the attack likelihood for each VM pair as independent evidence, then fuses these assessments across all pairings to produce a consolidated detection verdict. This multi-VM awareness addresses a blind spot in earlier models that evaluated VMs in isolation. Blockchain-verified distributed IDS: A distributed IDS [38] combines blockchain-verified transactions with a central coordinator unit, achieving 98.91% accuracy on the BoTIoT dataset and 99.41% on UNSW-NB15. The blockchain layer ensures tamper-resistant logging of detection events, which is useful in multi-tenant settings where trust between tenants cannot be assumed. The trade-off, however, is the overhead of transaction verification—an issue that grows with tenant density. Anomaly detection for APTs: Research on anomaly detection systems (ADS) [39] has shown that these systems can reduce the risks posed by advanced persistent threats that exploit multi-tenancy and cross-VM side channels. This work highlights that VM hopping is often just one step in a broader APT campaign, and that detection systems need to account for this sequential, multi-stage nature rather than treating each hop as an isolated event.

3.2.2. Prevention-Based Defenses Prevention-oriented approaches aim to eliminate the conditions that make VM hopping possible in the first place, either by controlling inter-VM communication or by disrupting co-residency. Frame tag communication control: The “frame tag” architecture [40, 41] uses three fields—Tenant Tag, Application Tag, and Flag—to identify the sender’s tenancy and application context for every inter-VM request. Each virtual machine (VM) has agents installed that check incoming traffic against trust-based criteria and discard packets that don’t comply. Although the need for in-VM agents results in deployment complexity, this deterministic tag-matching technique adds a security layer to inter-VM communication without depending on statistical detection. Page 4 of 19

From Hypervisor to Container: A Survey of Cloud Security

Security-aware VM allocation: A security-aware VM allocation approach [42] tackles the problem at the scheduling level. It refines VM placement criteria to reduce the probability that an attacker’s VM ends up on the same host as the target. Explicit security metrics for co-residency risk are defined, existing allocation policies are evaluated against these metrics, and a new placement strategy is proposed that balances workload distribution, power consumption, and security. The limitation is that a sufficiently motivated attacker who can launch many VMs may eventually achieve co-location through brute force. Dynamic VM migration (OSDF): The Online Smart Disguise Framework (OSDF) [43] takes inspiration from biological camouflage; much like a chameleon evading predators, OSDF uses frequent, dynamic VM live migrations to break co-residency before an attacker can exploit it. Built on OpenStack, the framework maintains active network connections during migrations. Its effectiveness was evaluated using VEAR, a mathematical model adapted from the SEIR epidemic framework, and results in a private cloud testbed showed measurable reductions in successful co-residency attacks. Proxy-based security (CLARUS): The CLARUS system [44] addresses VM hopping from a privacy-centric angle. It operates as a transparent proxy that ensures only authenticated users can access or interpret their cloud-stored data, while also monitoring for VM escape and VM hopping indicators. When suspicious activity is detected, CLARUS alerts cloud managers to intervene. Its strength lies in combining data-level privacy protection with infrastructure-level threat awareness. Software-Defined Perimeter (SDP): The SDP model [45] demonstrates that deploying a Software-Defined Perimeter within an NFV architecture can defend against multiple threat vectors simultaneously, including port scanning, DoS attacks, VM hopping, and remote hypervisor exploitation. The SDP restricts network visibility so that unauthorised entities cannot even discover potential targets, effectively shrinking the attack surface. Paired with physical access controls on VNF infrastructure, this approach showed improved resistance to lateral movement in virtualised network functions.

a multi-step attack chain that may also involve side-channel exploitation [46] or privilege escalation. This means that effective security necessitates integration with more comprehensive monitoring and isolation measures; point solutions that solely target hopping are insufficient. Although no single study in the existing literature has proven such an integrated deployment at scale, the most resilient posture is provided by combining preventive placement controls with runtime detection—for example, implementing security-aware allocation alongside evidence-fusion IDS. A system-level comparison of representative defense mechanisms is presented in Table 3.

3.3. Cache-Based Side Channel Attacks Cache-Based Side-channel attacks are sophisticated breaches that exploit vulnerabilities in hardware to obtain sensitive data or manipulate system operations. Side-channel cache attacks are particularly worrisome for public cloud platforms with multiple tenants. These attacks can be exploited by malicious VMs in this environment to gain unauthorised access to sensitive data from co-resident VMs that share the same underlying hardware. The aforementioned concern is particularly significant in the realm of Infrastructureas-a-Service (IaaS) cloud computing, wherein users share hardware resources. This underscores the critical need for enhanced security protocols and additional scholarly investigations into the realm of cloud security. These attacks offer a possible pathway for virtual machine (VM) egress, wherein a compromised VM could violate the isolation between VMs and gain access to data from other VMs running on the same physical hardware. As a result, cloud security would be significantly affected.

3.3.1. Hardware-Level Defence Mechanisms Hardware-level defences against cache side-channel attacks have evolved from early cache architecture redesigns (2009–2012) through partitioning-based isolation (2016) to runtime reconfiguration and randomisation techniques (2018–2021). These approaches operate at the processor or memory subsystem level, offering strong security guarantees but varying in deployment feasibility. A first category of defences involves redesigning cache architectures to eliminate the structural properties exploited by side-channel attacks. PLcache and RPcache [47] use 3.2.3. Cross-Paradigm Discussion preloading and random permutation hardware respectively Detection and prevention strategies for VM hopping each carry distinct trade-offs. Evidence-fusion and blockchain- to mitigate software cache attacks, though advanced attacks can still circumvent them. NewCache [48] is an architecture based IDS systems [37, 38] can accurately detect lateral that withstands contention-based attacks on both instruction movement, but they may have trouble with false positives and data caches while matching eight-way set-associative in intricate multi-VM architectures and rely on ongoing cache performance. STEALTHMEM [49] takes a systemmonitoring infrastructure. Preventive strategies frame tags level approach, managing locked cache lines per core to [40, 41], security-aware allocation [42], and dynamic migraprevent sensitive data eviction with a moderate 5.9% pertion [43] eliminate attack preconditions rather than reacting formance overhead. While architecturally robust, these apto attacks, but they impose architectural constraints: frame proaches require hardware adoption by processor vendors, tags need agents in every VM, allocation strategies can be limiting near-term deployment. brute-forced, and continuous migration consumes resources. Cache partitioning and isolation techniques offer a more A practical observation from the literature is that VM deployable alternative by leveraging existing hardware feahopping rarely operates in isolation. It is often one stage in tures. CATalyst [50] repurposes Intel’s Cache Allocation Swapnil Baviskar et al.: Preprint submitted to Elsevier

Page 5 of 19

From Hypervisor to Container: A Survey of Cloud Security Table 3 System-Level Evaluation of VM Hopping Defenses under the ADPO Maturity Framework Mechanism & Citation Evidence-Fusion IDS [37]

A 2

D 2

P 2

O 2

Primary System Control Dempster-Shafer flow-evidence modeling

Blockchain IDS [38]

3

1

1

1

Ledger-based tamper-resistant event tracking

Frame Tag Control [40]

2

2

2

2

Tenancy-aware packet tag verification

Security Allocation [42]

2

2

3

3

Security-aware VM scheduling heuristics

OSDF live migration [43]

2

1

1

2

Epidemic-driven dynamic host shuffling

Technology (CAT) to partition the Last-Level Cache (LLC) into secure and insecure regions, preventing malicious code from displacing secure pages. This hybrid hardware-software approach effectively mitigates LLC-based PRIME+PROBE and FLUSH+RELOAD attacks with low performance degradation. A Hardware Transactional Memory (HTM) defense [51] exploits Intel TSX to suspend transactions required for cache side-channel attacks, achieving minimal overhead on cryptographic operations, though the approach is incompatible with Hyper-Threading and depends on secure source code availability. Runtime reconfiguration and randomisation represent the most recent hardware-level defence category. Adaptive cache reconfiguration [52] reduces side-channel attack accuracy by 44% through dynamic reconfiguration of independent memory chunks using Petri net-based analysis. Lightweight system-level randomisation [53] of processor frequency and prefetcher activities reduces performance overhead from 32.66% to 20% compared to prior alternatives without requiring hardware modifications. Shuffler schedulers [54] address the scheduling dimension by spreading CPU time unpredictably across vCPUs, minimising crossVM information leakage while maintaining resource utilisation. Detection-oriented hardware approaches complement these preventive mechanisms. SCADET [55] achieves a 100% true positive rate for Prime+Probe detection with an average false positive rate of 7.4%, while CSDA [56] focuses on resource utilisation impact analysis. However, a systematic review [4] cautions that Hardware Performance Counters (HPCs), increasingly used for security monitoring, suffer from non-determinism and overcounting issues that may undermine HPC-based detection reliability. Across these approaches, a clear trade-off emerges: architectural redesigns (NewCache, PLcache) offer the strongest guarantees but require industry adoption, while softwarecompatible techniques (adaptive caches, randomisation) are more deployable but provide weaker assurances against sophisticated adversaries.

3.3.2. Hypervisor and Software-Layer Detection While hardware-level defences modify processor behaviour, a parallel body of work addresses cache sidechannel detection at the hypervisor and software layers. These approaches are generally more deployable, requiring no hardware changes, and have evolved from early resource Swapnil Baviskar et al.: Preprint submitted to Elsevier

Key Quantitative Metric / Guarantee Eliminates conflicting alarms with multi-source rules 98.91% accuracy (BoT-IoT); 99.41% (UNSWNB15) Deterministic lateral path filtration; zero false positives Minimizes co-residency probability with 95% confidence Shuffles VM locations before attack profiling completes

utilisation analysis (2013–2016) to sophisticated machine learning-based classification (2018–2025). A first group of solutions provides autonomous, lightweight monitoring that integrates into existing cloud deployments. CacheShield [57] protects legacy code without hypervisor or OS modifications, using hardware performance counters and change-point detection to identify DoS and cache attacks with low false positive rates. CloudRadar [58] combines signature-based detection for protected VMs with anomalybased monitoring of co-located VM behaviours, achieving millisecond-level detection without requiring any system modifications. Transparent hypervisor-driven implementations [3] dynamically prevent side-channel threats, balancing cache partitioning and warming to maintain system performance. Machine learning-based approaches achieve the highest reported detection accuracies. NIGHTsWATCH [59] uses statistical classification models with hardware performance counters, achieving 99.51% accuracy under no-load and 99.44% under high-load conditions. A KVM event-driven pipeline [60] processes event data with machine learning to differentiate CSCa from non-CSCa datasets, achieving an AUC of 0.99 even against Flush+Flush attacks. A multi-architecture ensembled detection system [61] combines attention-based prioritisation with anomaly encoding, achieving 98.65% accuracy on the ASCAD dataset. A vCPU monitoring approach [62] measures vCPU cycles, virtual memory utilisation, and cache miss rates to detect Prime+Probe, Flush+Flush, and Flush+Reload attacks with 92.5% accuracy, surpassing both the two-stage system (85%) and CloudRadar (88%). Alternative detection paradigms include fuzzy logic and filter-based methods. A fuzzy-logic controller [63] uses log-file-derived linguistic variables, achieving precision of 78.15–82.16% at varying intervals. A Bloom Filter approach [64] uses cache miss sequences as attack signatures, outperforming existing algorithms with reduced execution time. SpyDetector [65] takes a semi-supervised anomaly-based approach, monitoring shared resource contention levels with runtime overheads of only 0.49–3.58%. A server-side defence mechanism [66] protects against Prime+Trigger+Probe attacks in a Xen hypervisor environment without client-side modifications. Two-stage detection architectures combine coarse-grained filtering with fine-grained analysis. A URI-based detection Page 6 of 19

From Hypervisor to Container: A Survey of Cloud Security Table 4 System-Level Evaluation of Cache Side-Channel Defenses under the ADPO Maturity Framework Mechanism & Citation STEALTHMEM [49] CATalyst [50] Adaptive Caches [52] Shuffler Schedulers [54]

A 2 3 2 2

D 2 2 0 2

P 2 3 3 3

O 3 3 3 3

Primary System Control Hypervisor-level cache line locking Intel CAT-based hardware LLC partitioning Silicon-level dynamic set permutation Randomized vCPU rescheduling intervals

HTM (Intel TSX) [51] CacheShield [57] NIGHTsWATCH [59]

3 2 3

1 3 2

3 3 3

3 3 2

TSX transaction hardware encapsulation User-space performance counter loop Hardware counter statistical classifier

CloudRadar [58] Two-stage VMI [68]

2 3

3 1

3 3

2 2

Signature-based out-of-band VMI Coarse-to-fine hypervisor memory correlation

system [67] implements shape tests for hosts and regularity tests for guests using a utilisation rate index, maintaining robust detection with low computational cost. An extended VMI-based detector [68] combines virtual machine introspection with hardware performance counters, achieving 96.7% precision and 95% recall (98.9% F1-score with adjusted sampling) while remaining imperceptible to attackers at the hypervisor layer.

Key Quantitative Metric / Guarantee Complete eviction mitigation for stealth pages Guarantees no cache evictions between domains Reduces correlation accuracy by 44% Disrupts attacker-victim co-scheduling synchronization Aborts transaction instantly upon cache eviction Low false positives during standard execution 99.51% detection under idle; 99.44% under heavy load Millisecond-level detection latency; no VM mod 96.7% precision, 95% recall (98.9% F1-score)

3.4. Container Escape / Container Breakout A study of five commercial platforms [69] developed a technique to rate the security of cloud container services. Some containers included weak security defences and deactivated Seccomp. KASLR bypass was effective in every container, but because attackers have limited access to essential host OS files, leaving public cloud containers is still difficult. It is advised to activate and configure kernel mechanisms (Seccomp, Capabilities, and MAC), secure sensitive files with KASLR, fix vulnerabilities quickly, and take different kernel versions into account. Although attackers might eventually exploit memory corruption vulnerabilities for ROOT privileges despite the fact that public cloud systems are more resistant to privilege escalation, this highlights the need of timely upgrades and vulnerability mitigation [69].

3.3.3. Cross-Paradigm Comparative Discussion Comparing hardware-level and software-layer defenses reveals a fundamental trade-off between security strength and deployment feasibility. Hardware approaches such as cache redesigns (NewCache, PLcache) and partitioning schemes (CATalyst, HTM) provide strong isolation guarantees but require processor vendor adoption or specific hardware features, limiting near-term deployment [47, 48, 3.4.1. Intrusion Detection Systems 50]. In contrast, software and hypervisor-layer detectors Early container intrusion detection efforts (2015–2017) (CacheShield, CloudRadar, NIGHTsWATCH) can be defocused on rule-based profiling and automated policy genployed on existing infrastructure and achieve detection accueration [70, 71], while more recent work (2019–2023) has racy up to 99.51%, but they introduce continuous monitoring shifted toward machine learning-driven anomaly detection overhead and can only detect attacks after leakage has and automated runtime monitoring [72, 73, 74]. begun—they cannot prevent it [57, 58, 59]. A foundational class of container IDS relies on beDetection accuracy across software approaches ranges havioural profiling to define acceptable operations. LiCfrom 78% for fuzzy-logic methods [63] to 99.51% for MLShield [70] generates rule-based profiles from traced exebased classifiers [59], with machine learning consistently cutions, restricting containers to observed behaviours, while outperforming statistical baselines. However, all ML-based Starlight [71] automates policy generation and adapts to ledetectors depend on representative training data, and the gitimate workload changes. The Most Privileged Container lack of standardised cache side-channel datasets limits the (MPC) framework [75] extends this paradigm by deploying generalisability of reported results. Hardware Performance a privileged watchdog container that enforces access control Counters (HPCs), which underpin many detection tools, also through blacklist databases and runtime monitoring. A rulesuffer from non-determinism that can undermine reliability based monitoring evaluation [76] complements these ap[4]. proaches by assessing open-source tools such as Sysdig and The most practical defense strategy combines both paradigms:Falco, targeting misuses including container breakout via hardware partitioning (e.g., Intel CAT) to contain leaknsenter. Although effective against known attack patterns, age channels, paired with software-layer monitoring (e.g., these approaches share a common limitation: they struggle NIGHTsWATCH, CloudRadar) to detect residual attack to detect novel or zero-day attacks that fall outside preattempts. Optimising this combination across diverse workdefined behavioural profiles. loads, minimising false positives in production environTo address the limitations of static rule sets, several ments, and adapting detection to evolving cloud architecstudies employ machine learning for anomaly detection in tures remain open challenges. A quantitative comparison of container environments. A graph-based system call model representative defense mechanisms is presented in Table 4. [73] achieves the highest reported detection performance, with AUC scores reaching 99.97% for container breakout scenarios. A real-time syscall classifier [72] handles nonlinear syscall sequences, maintaining false positive rates Swapnil Baviskar et al.: Preprint submitted to Elsevier

Page 7 of 19

From Hypervisor to Container: A Survey of Cloud Security

between 0.02 and 0.12. An n-gram analysis approach [77] reports 87–97% accuracy across SQL injection, DoS, and container breakout scenarios. Unsupervised VMI techniques [74] represent a departure from the supervised and statistical methods prevalent in earlier work. A hybrid scanning approach [78] demonstrates that combining static scanning with dynamic anomaly detection raises the detection rate to 86% (24 of 28 exploits), compared to only three vulnerabilities detected by static analysis alone. Beyond detection, two frameworks address the full container lifecycle. A managed containers architecture [79] performs pre-deployment vulnerability analysis and enables rollback to secure states following an attack, without requiring application code changes. An automated Fault and Intrusion Tolerance (FIT) framework [80] extends to accidental faults, though its scalability remains constrained by the cost of intensive verification on virtualised hosts. RSDS [81] approaches the problem from a kernelhardening perspective, reducing unnecessary system calls by 69.27–85.89% through combined static and dynamic analysis. Docker’s Seccomp support (from version 1.10) provides the foundation for such restrictions, though coverage gaps remain for interpreted languages and non-ELF executables. Across these approaches, detection performance varies considerably: graph-based HIDS achieves AUC scores above 99% [73], while hybrid static-dynamic scanning reaches 86% [78] and n-gram methods report 87–97% [77]. A critical gap persists in the availability of representative datasets for container-specific intrusion detection [82], limiting the generalisability of reported results across diverse multitenant environments.

3.4.2. System Call Hardening Since containers share the host kernel, system calls represent the primary interface through which containerised processes can exploit kernel vulnerabilities to achieve escape. Early hardening efforts (2017–2019) focused on phase-aware Seccomp filtering and sandbox mining [83, 84], while recent work (2020–2023) has advanced toward automated profile generation, runtime integrity enforcement, and architecture-level scheduling [85, 86, 87]. A first line of defence involves quantifying and measuring system call exposure. SecQuant [88] combines exploit code analysis with system call reachability checking to produce a Container System call Exposure Measure (CSEM), demonstrating that secure runtimes are 4.2–7.5× more secure than their default counterparts. A sequencebased syscall filtering approach [89] extracts 471 patterns from 106 exploit programs, showing that 60–86% of exploits not blocked by Confine’s profiles could be mitigated through sequence matching. A process-level access control system [90] enforces access control for host file interactions and uses namespace monitoring to detect escape attempts in IoT environments. A second category of defences enforces runtime integrity at the system call interface. System Call Integrity [86]

Swapnil Baviskar et al.: Preprint submitted to Elsevier

validates three contexts—Call Type, Control Flow, and Argument Integrity—through BASTION, achieving negligible overhead of 0.60–2.01% while protecting 20 critical system calls. At the orchestration level, SySched [87] is a syscallaware container scheduler that reduces the host attack surface by 20% and victim containers by up to 48% through strategic placement based on system call consumption profiles. SHARD [91] operates at the kernel level, specialising exposed kernel code per application and stopping 90% of attacks with 0–36% overhead via control-flow integrity (CFI). The largest body of work focuses on automated Seccomp profile generation to minimise the attack surface. Confine [85] uses static code analysis to disable 145+ system calls across 150 Docker images, neutralising 51 known kernel CVEs without requiring runtime workload data. Prof-gen [92] extends this by combining static and dynamic analysis, producing profiles 20.2% more compact than Confine while blocking 36.4% more CVE-linked system calls. SPEAKER [83] takes a phase-aware approach, differentiating boot-time from runtime system calls to eliminate over 50% of calls for data store containers. SysCap [93] reduces 62% of unnecessary system calls across 193 Docker images while generating capability lists averaging 5.3 per image. For production deployment, a sandbox mining approach [84] achieves 96.4– 99.8% syscall coverage, while a CI/CD pipeline integration [94] automates Seccomp profiling using Container Tracing, Exit Check, and Fuzzing stages. Quantitatively, the automated profile generators show a clear evolutionary trajectory: from SPEAKER’s phaseaware filtering (2017) to Confine’s static analysis (2020), Prof-gen’s hybrid approach (2021), and SysCap’s imagelevel tooling (2022), each iteration improving coverage and compactness. However, static analysis approaches remain limited in handling interpreted languages and dynamically loaded libraries, and the trade-off between profile strictness and application breakage remains an open challenge across all methods.

3.4.3. Namespace and CGroup Isolation Linux namespaces and cgroups form the foundational isolation primitives for containers, yet both have been shown to harbour exploitable weaknesses. Research in this area spans from offensive exploitation studies that quantify the severity of isolation failures to defensive mechanisms that detect or prevent namespace and cgroup abuse. On the offensive side, a cgroup circumvention study [95] demonstrates that cgroup resource accounting can be bypassed by separating processes from their originating cgroups, enabling containers to exceed their resource limits by up to 200× while degrading co-resident container performance by 95%. Five case studies on Docker systems reveal feasible denial-of-service, resource-freeing, and covertchannel attacks in multi-tenant deployments. An analysis of 11 container runtimes across 59 CVEs [96] identifies nine PoC vulnerabilities for 13 CVEs—all stemming from host components being exposed inside containers. A user namespace defence is proposed that blocks seven of nine Page 8 of 19

From Hypervisor to Container: A Survey of Cloud Security

vulnerabilities by modifying the runC architecture to use file descriptors instead of string-based mount paths, eliminating race conditions. A comprehensive vulnerability taxonomy [97] classifies 223 successful container vulnerabilities, demonstrating that 56.82% of 88 common vulnerabilities can breach containers with default settings. This analysis reveals that kernel security features (Capability, Seccomp, MAC) are more effective than container isolation techniques for preventing privilege escalation, and identifies a characteristic 4-step attack model for such exploits. A namespace status inspection defense [98] focuses specifically on Docker’s namespace architecture, proving effective against both known attacks and zeroday vulnerabilities, though Docker’s shared-kernel design remains a fundamental limitation. For real-time detection, PACED [99] defines crossnamespace events and uses provenance-based graph queries to identify container-escape attacks with near-perfect precision and zero false negatives on both Docker and Kubernetes. HoneyContainer [100] takes a deception-based approach, detecting all shell command injection events across 214 webshell files while providing cgroup-based finegrained resource control with low overhead. A containerbased honeypot approach [101] extends the deception paradigm by simulating escape scenarios using fake host systems and partition renaming. An evaluation of runtime monitoring tools [102] assesses open-source tools (Sysdig, Falco) for detecting misconfigurations and privilege escalation, using containerization-specific properties and blacklist filtering to minimise data collection overhead. Despite these advances, container escape vulnerabilities remain fundamentally difficult to discover and mitigate. The shared-kernel architecture creates an inherent tension between performance and isolation, and the impossibility of patching all kernel vulnerabilities in production environments underscores the continued need for layered runtime defences.

3.4.4. Cross-Paradigm Comparative Discussion The defence mechanisms surveyed above reveal a consistent trade-off between security coverage and operational overhead. Rule-based IDS and behavioural profiling approaches (LiCShield, Starlight, MPC) offer low-overhead protection against known attack patterns but lack adaptability to zero-day threats. Machine learning-based detectors achieve higher accuracy—up to 99.97% AUC [73]—but require representative training datasets that remain scarce for container-specific scenarios [82]. System call hardening tools (Confine, Prof-gen, SysCap) effectively narrow the kernel attack surface, yet static analysis limitations for interpreted languages and the risk of application breakage from overly restrictive profiles persist across all approaches. At the namespace and cgroup level, user namespace defences and provenance-based detection (PACED) demonstrate near-perfect precision, but their dependency on runtime architectural modifications may hinder adoption. Expanding these defence measures to production scale requires Swapnil Baviskar et al.: Preprint submitted to Elsevier

addressing three open challenges: (1) scalability across heterogeneous container orchestration platforms, (2) adaptive profiling for dynamic workloads, and (3) standardised evaluation benchmarks for container security. A comparison of defence mechanisms for container escape is presented in Table 5.

3.5. Vulnerabilities In Container Images Unlike virtual machines that abstract hardware, containerized security controls are heavily frontloaded into the software supply chain. Containers are constructed from layered images containing a base operating system, library dependencies, application packages, and environment configurations. Any security defect introduced in an upstream layer automatically propagates to all derived downstream container instances. Consequently, vulnerabilities in container images present a systemic risk, serving as potential entry points for lateral movement or container escape.

3.5.1. Static Vulnerability Scanning Static scanning inspects container images at rest by parsing package manifests, file hashes, and configuration settings to identify known security vulnerabilities. A largescale scanning study [103] evaluated the security state of public container images by scanning over 10,000 images using a data analytics platform. The analysis revealed that 92% of the public images contained an average of 10 vulnerable packages, while 99% exhibited compliance violations, highlighting the prevalence of software defects in public registries. To address vulnerability tracking during image transfer, DIVDS (Docker Image Vulnerability Detection System) [104] extracts layer metadata and vulnerability information during upload and download phases. While effective for inventory tracking, DIVDS relies on static analysis via Clair, rendering it blind to runtime anomalies. To improve scanning accuracy during build-time, DAVS [105] parses Dockerfiles to identify Potentially Vulnerable Files (PVFs) introduced during custom compilation or installation steps. By targeting files added outside standard package managers, DAVS achieved a 68% vulnerability detection rate on realworld images, outperforming standard static analysis tools. The challenge of scanning application-level dependencies rather than just OS-level packages was studied in an evaluation of Java-based container applications on Docker Hub [106]. The results showed that while OS-level packages were well-cataloged, vulnerabilities in application packages often went undetected, resulting in a low Detection Hit Ratio (DHR) of 13% for Microscanner, 36% for Clair, and 65% for Anchore. To establish standard evaluation criteria for image scanners, UBCIS (Ultimate Benchmark for Container Image Scanning) [107] provides a benchmark framework that categorizes vulnerabilities based on their relevance to containerized architectures, allowing developers to assess the ability of different scanning tools to identify obsolete software packages. Finally, SEAF [108] leverages a Global Relationship Tree (GRT) to analyze package and configuration dependencies. When applied to Docker Hub, SEAF Page 9 of 19

From Hypervisor to Container: A Survey of Cloud Security Table 5 System-Level Evaluation of Container Escape Defenses under the ADPO Maturity Framework Mechanism & Citation User Namespace Defence [96]

A 2

D 1

P 3

O 3

Primary System Control runC unprivileged root mapping

PACED [99]

3

1

3

2

Provenance tracking of cross-namespace events

HoneyContainer [100]

3

2

3

2

Command injection redirection

Syscall Integrity [86]

2

2

3

3

BASTION compiler flow & argument validation

SySched [87] Confine [85]

2 2

1 3

3 3

3 3

Syscall-aware container scheduling Static binary dependency analysis

Prof-gen [92]

2

2

3

3

Static & dynamic profile generation

detected 36,688 security issues, including malware and misconfigurations, across 26,153 container images.

3.5.2. Runtime, Behavioral, and ML-Based Detection While static scanning helps secure images prior to deployment, it cannot identify zero-day exploits, dynamic backdoors, or malicious configurations executed at runtime. Docker-sec [109] bridges the gap between static definitions and runtime enforcement by automatically generating AppArmor profiles based on container image analysis to restrict system call access and enforce access control policies at runtime. Machine learning models have also been applied to detect embedded malware. A supervised classification approach [110] evaluated several algorithms, including Decision Trees, Random Forests, and XGBoost, to detect keylogger code in custom container images, achieving high classification accuracy by analyzing specific system and library calls. Similarly, a hybrid detection mechanism [111] counters web backdoors that evade signature-based tools like ClamAV. By applying a Random Forest classifier to code features such as entropy and coincidence index, the approach identifies zero-day backdoors with a low false positive rate. For runtime behavioral monitoring, a container-level anomaly detection system [112] evaluated in multi-tenant environments applies machine learning to Bag of System Calls (BoSC) sequences with a sliding window size of 30, achieving a 99.8% F-measure in distinguishing malicious execution traces from normal application behavior. 3.5.3. Supply Chain Security and Continuous Integrity Protecting containerized environments requires security verification across the entire lifecycle, from build-time dependencies to deployment registries. A large-scale analysis of secret leakage [113] scanned over 337,000 public and 8,000 private container images. The study found that 8.5% of images contained exposed API keys, private keys, or other credentials, illustrating how human errors during build phases bypass standard code reviews. To track the origin of vulnerabilities, ZeroDVS [114] builds image source graphs to establish parent-child traceability across image layers, tracing vulnerabilities back to parent images to ensure that security patches applied at the base layer propagate correctly. A cloud-native continuous security methodology [115] uses correlation-based rules to scan microservices and container Swapnil Baviskar et al.: Preprint submitted to Elsevier

Key Quantitative Metric / Guarantee Blocks 7 of 9 proof-of-concept exploits across 59 CVEs Near-perfect precision; zero false negatives under tests 100% detection across 214 tested webshell exploits Protects 20 critical syscalls; 0.60–2.01% execution overhead Reduces host attack surface by 20% Disables 145+ redundant syscalls, blocks 51 CVEs Blocks 36.4% more CVEs with 20.2% more compact profiles

images throughout the deployment pipeline, ensuring that runtime configuration changes do not compromise the system’s baseline security posture.

3.5.4. Cross-Paradigm Comparative Discussion The analysis of container image defense mechanisms reveals clear trade-offs between static pre-deployment checks and dynamic runtime monitoring. Static scanners [105, 104] introduce minimal operational overhead and integrate seamlessly into CI/CD pipelines, but they cannot identify zero-day exploits or active backdoors. In contrast, runtime anomaly detectors [112] and machine learning classifiers [111] offer high accuracy against unknown threats but demand substantial host computational resources and require continuous model retraining on representative datasets. Proactive enforcement tools like AppArmor profile generation [109] offer strong security guarantees but risk disrupting legitimate application workflows if configured incorrectly. Consequently, securing containerized systems requires a multi-layered approach: combining parent-image traceability [114] and static vulnerability scanning [108] during build phases with continuous behavioral intrusion detection [112] at runtime. A comparison of representative defense mechanisms for container image vulnerabilities is presented in Table 6.

3.6. Distributed Denial of Service (DDoS) Attacks Distributed Denial of Service (DDoS) attacks present a critical threat to cloud environments, exploiting resource sharing, dynamic orchestration, and multi-tenant vulnerabilities to disrupt service availability. Within a cloud paradigm, DDoS attacks manifest across multiple dimensions: (i) volumetric attacks (e.g., UDP and ICMP floods) that overwhelm network bandwidth, (ii) protocol-level attacks (e.g., TCP SYN floods) that saturate connection state tables, (iii) application-layer attacks (e.g., slow HTTP requests) that drain application server threads, and (iv) cloud-native vectors like Economic Denial of Sustainability (EDoS) and Yo-Yo attacks that exploit auto-scaling policies to cause severe financial damage rather than simple service outages. Effective defense requires high-performance, scalable detection and mitigation systems. Researchers have proposed various approaches, spanning host-based, network-based, software-defined networking (SDN), and machine learning Page 10 of 19

From Hypervisor to Container: A Survey of Cloud Security Table 6 System-Level Evaluation of Container Image Vulnerability Defenses under the ADPO Maturity Framework Mechanism & Citation SEAF (GRT) [108] Docker-sec [109]

A 2 2

D 2 2

P 3 3

O 2 3

Primary System Control Global Relationship Tree dependency graphs Build-time AppArmor profile generation

DIVDS [104]

1

3

3

3

Registry-level metadata transfer scanners

DAVS [105]

2

2

3

3

UBCIS [107]

0

3

3

3

Dockerfile syntax Potentially Vulnerable File analysis Scan quality benchmarking framework

ML Code Scan [110] Secret Detection [113]

3 2

2 2

1 3

2 3

Supervised Decision Tree/XGBoost static models Regex credential scans in registry pipelines

ClamAV + ML [111] ZeroDVS [114]

2 2

2 1

2 3

2 2

Code feature entropy & coincidence index classifier Layered parent-child traceability graphs

Anomaly IDS [112]

3

1

1

2

Dynamic sliding-window Bag-of-Syscalls models

Key Quantitative Metric / Guarantee Identified 36,688 issues across 26,153 images Non-intrusive zero-day containment at host interface Extracts static package CVEs during upload/download 68% vulnerability detection rate (outperforms Clair) Offline benchmark of comparative scanning precision Up to 100% detection of custom keylogger code Revealed credential leaks in 8.5% of public Hub images Accurate zero-day backdoor anomaly classification Traces dependency lineage to ensure base layer patching 99.8% F-measure in distinguishing execution anomalies

(ML) frameworks, to secure cloud infrastructure against these dynamic threats.

Networks (CNN), reporting high accuracies of 96% and 99% respectively.

3.6.1. Host-Based Intrusion Detection Systems Host-based Intrusion Detection Systems (HIDS) secure virtualized environments by monitoring internal virtual machine (VM) logs, system calls, and resource utilization. In this context, the Real-Time DDoS flood Attack Monitoring and Detection (RT-AMD) model utilizes incremental learning and cloud testing to assess algorithms like Naive Bayes, K-Nearest Neighbor (KNN), and Random Forest against DDoS floods [116]. A MapReduce-based architecture [117] utilizes statistical analysis to detect HTTP GET flood attacks, achieving an 88.04% detection rate compared to Snort’s 69.84%. To balance signature and anomaly detection, the HIDCC model [118] employs a four-phase intrusion prevention strategy, using Snort for signature matching, anomaly-based classifiers for zero-day identification, and Apriori association rule mining to update known attack patterns, achieving 99.38% accuracy and a low 0.7% false alarm rate. Similarly, an optimized feature evaluation model [119] optimizes feature values using logistic regression and integrates classifiers like decision trees, neural networks, and linear discriminant analysis through Bagging to achieve a 97.51% performance improvement over baseline models on the NSL-KDD dataset. Other host-based approaches focus on reducing feature dimensionality and processing latency. A parallel cumulative ranker algorithm [120] integrates SVM binary classification with active learning and distributed feature selection, achieving 92%–97% feature recognition accuracy while reducing computational times by 71%–85% across CAIDA and ISCX-IDS datasets. A Fuzzy c-means clustering approach [121] demonstrates that Fuzzy c-means clustering delivers faster classification compared to traditional classifiers like SVM, KNN, and Decision Trees. In terms of microfeature analysis, the Smart Detection system [122] monitors network traffic metrics, using a Random Forest algorithm to achieve a 99.93% classification accuracy with just 20 refined traffic variables. Furthermore, a hybrid host-level defense [123] combines SVM and Convolutional Neural

3.6.2. Network-Based Intrusion Detection Systems Network-based Intrusion Detection Systems (NIDS) analyze traffic flows, packet headers, and network-level anomalies across the cloud infrastructure. For general protection, commercial cloud providers offer managed offerings, such as Azure DDoS Protection and Google Cloud Platform (GCP) Cloud Armor, which provide automated detection, realtime traffic monitoring, and web application firewalls targeting volumetric and protocol-level threats [124]. To assess NIDS vulnerability, an adversarial framework [125] uses Wasserstein Generative Adversarial Networks (WGAN) and SHAP feature analysis to generate perturbed DDoS traffic that successfully evades ML-based intrusion detectors. On the defense validation side, a simulated attack study [126] uses the Low Orbit Ion Cannon (LOIC) program to validate the capabilities of Snort in monitoring virtualized cloud environments. To address multi-sensor and deep learning requirements, several advanced architectures have been developed. A three-sensor network architecture [127] monitoring ingress, external server, and internal network flows uses genetic algorithms for feature selection and an Artificial Neural Network (ANN) for flow classification, achieving a 99.98% detection rate on the CAIDA dataset. For SDN environments, FlowGuard [128] combines a flow filter (for signature identification) and a flow handler (for routing benign traffic) with LSTM and CNN models, achieving a 98.9% identification accuracy against zero-day attacks. Similarly, NIMBUS [129] integrates VM-level auto-scaling and SDN controller programming to isolate and distribute high-volume DDoS traffic. A software-defined framework [130] combines SelfOrganizing Maps (SOM) and SVM classifiers to protect service function chaining (SFC) against resource saturation, outperforming standalone SVMs to achieve a 99.30% classification accuracy. Evaluating these architectures is often limited by the availability of high-fidelity datasets and proactive deployment methodologies. To address this, the ISOT-CID dataset

Swapnil Baviskar et al.: Preprint submitted to Elsevier

Page 11 of 19

From Hypervisor to Container: A Survey of Cloud Security

[131] compiles terabytes of production-level cloud traffic from an OpenStack environment to facilitate VM-level DoS and masquerade attack analysis. Moving beyond reactive detection, a proactive defense system [132] prototyped on Amazon AWS dynamically shuffles server allocations, demonstrating a 95% probability of maintaining service availability. Furthermore, the RDAER model [133] is a hybrid SDN framework that uses Recursive Feature Elimination and time-series forecasting (ARIMA/exponential smoothing) at the switch level to perform early DDoS detection with low latency, although its multi-stage logic introduces deployment complexity.

3.6.3. Comparative Synthesis of Classic Intrusion Detection Approaches A comparative analysis of HIDS and NIDS reveals distinct operational trade-offs in cloud environments. HIDS architectures (such as RT-AMD, HIDCC, and smart RF classifiers) excel at detecting highly localized attacks, virtual machine escape, and host-level system call anomalies, offering granular insights with high classification accuracy (frequently exceeding 99%). However, their heavy agent footprint imposes non-trivial CPU and memory overhead on individual host hypervisors. Conversely, NIDS frameworks (including FlowGuard, NIMBUS, and multi-sensor neural networks) provide centralized, stack-wide visibility that is crucial for detecting distributed volumetric attacks and interVM traffic anomalies. Yet, their network-wide monitoring can lead to scalability bottlenecks under massive traffic volume, and their reliance on raw packet capture raises privacy and resource isolation concerns. Consequently, modern research is increasingly pointing toward hybrid, multi-layered architectures that coordinate edge-level network filtering with VM-level introspection to secure multi-tenant cloud systems. 3.6.4. Thematic Synthesis of Recent Defense Mechanisms To counter the increasing complexity of cloud DDoS attacks, recent literature (2022–2024) has shifted from simple signature matching toward specialized architectural strategies. We classify these contemporary works into four primary thematic pillars: 1. Software-Defined Networking (SDN) Enabled Defenses: Modern SDN-based architectures leverage open flow tables and centralized controllers to perform real-time traffic filtering. The EDOS-TCP SYN mitigation model (EDOSTSM) [134] dynamically analyzes TTL field values and applies binomial probability to isolate spoofed IP traffic, successfully mitigating Economic Denial of Sustainability (EDoS) attacks in an OpenStack environment. This works in tandem with proactive SDN switch-level controllers such as RDAER [133], highlighting a clear research focus on software-defined routing policies to throttle attacks before they reach virtualized hosts. 2. Moving Target Defense and Resource Isolation: Rather than relying solely on detection, active defenses aim to Swapnil Baviskar et al.: Preprint submitted to Elsevier

alter the cloud attack surface dynamically. A comprehensive Moving Target Defense (MTD) framework [135] systematically classifies techniques like dynamic shuffling, diversity, and redundancy to increase uncertainty for attackers. Practically, an evaluation of resource separation [136] explored physical machine (PM) and virtual machine (VM) level service separation, demonstrating that physical-layer isolation is highly effective at maintaining service availability and reducing request latency for benign users, though it demands additional physical infrastructure compared to containerlevel separations. 3. Cloud-Native and Kernel-Layer Filtering: To minimize host performance degradation, modern frameworks perform traffic analysis directly inside the operating system kernel. A lightweight Kubernetes DDoS filtering mechanism [137] utilizes Extended Berkeley Packet Filter (eBPF) and eXpress Datapath (XDP) to filter malicious packets at the network driver level with minimal CPU overhead. For secure auditing, a Third-Party Auditor (TPA) framework [138] integrates with cloud datacenters using an interactive threshold anomaly detection strategy to bypass excessive filtering stages. Additionally, an evaluation of packet filtering and circuit-level gateway firewalls [139] demonstrated up to 98.88% ICMP flood reduction in edge environments, illustrating the potential of kernel-level and gateway filtering. 4. High-Accuracy Anomaly Detection Algorithms: Recent work has also introduced advanced statistical and machine learning classifiers to distinguish attacker and user profiles. The ID3-MMDP method [140] pairs the Iterative Dichotomiser 3 (ID3) algorithm with a Maximum Multifactor Dimensionality Posteriori estimator to achieve superior response times and detection accuracy compared to standard Naive Bayes baselines. In a similar vein, a hybrid algorithm [141] integrating Multivariate Correlation Analysis and the Spearman Coefficient achieves a 99% detection accuracy on the KDD Cup 99 dataset by identifying fine-grained statistical correlations in network streams.

3.6.5. Cross-Paradigm Comparative Discussion The evaluation of both classic and emerging DDoS defense mechanisms underscores their direct influence on the Availability dimension of the CIA triad, which remains the primary target of DDoS attacks. Cloud-native vulnerabilities, such as Yo-Yo attacks [142], demonstrate how attackers can exploit dynamic auto-scaling behaviors to cause Economic Denial of Sustainability (EDoS), creating severe service degradation and financial overhead even after the malicious traffic has ceased. While cloud providers offer managed infrastructure tools like AWS Shield and GCP Cloud Armor to mitigate these risks [143], experimental studies (such as DoS testing with LOIC on GCP [144]) reveal that automated detection by public cloud providers can exhibit significant latency (e.g., up to 45 minutes), leaving virtual systems vulnerable during critical initial phases.

Page 12 of 19

From Hypervisor to Container: A Survey of Cloud Security Table 7 Quantitative Systems-Level CIA Severity Matrix for Cloud Vulnerabilities Vulnerability Class VM Escape

C 5

I 5

A 5

VM Hopping

4

4

3

Cache Side-Channel

5

1

1

Container Breakout

4

4

4

Container Image Vulns

3

3

3

EDoS / Volumetric DDoS

1

2

5

System-Theoretic Cybernetic Rationale High-privilege isolation boundary breakout; full VMM control. Multi-tenant lateral boundary failure; pivot to coresident VMs. Microarchitectural timing leakage; passive covert feedback loop. Shared-kernel boundary collapse; host OS namespace execution. Supply-chain vulnerability propagation through layered images. Volumetric capacity saturation; EDoS auto-scaling exploitation.

4. Discussion on CIA Triad To secure complex cloud ecosystems, we must understand how specific isolation failures propagate across Confidentiality (C), Integrity (I), and Availability (A) state variables. Table 7 establishes our quantitative Systems-Level CIA Severity Matrix, assigning 1–5 impact scores backed by a system-theoretic cybernetic rationale. Confidentiality (C): Microarchitectural side-channels and boundary escapes pose the highest risk to confidentiality. Cache-based side-channels exploit shared hardware state transitions (e.g., CPU caches) to exfiltrate cryptographic keys out-of-band, acting as a passive timing feedback loop. Similarly, VM and container escape vulnerabilities represent a complete breakdown of isolation boundaries, allowing adversaries to read memory blocks across different guest domains directly. Integrity (I): Integrity degradation occurs when an attacker achieves arbitrary code execution outside their security container. A high-severity VM escape allows a malicious tenant to alter hypervisor memory space, compromising the execution path of the VMM controller itself. At the application layer, backdoored container image dependencies pollute the software supply chain, propagating malicious control loops into production environments. Availability (A): While volumetric DDoS attacks directly target availability by flooding communication links, modern cloud-native systems are uniquely vulnerable to auto-scaling loop manipulation. Volumetric spikes and EDoS attacks exploit elastic auto-scaling policies to drain client financial reserves (Yo-Yo attacks) rather than causing simple service outages, converting system feedback mechanisms into financial failure loops.

5. Synthesis of Gaps and Open Challenges By evaluating defense mechanisms across virtualization, containerization, and network-wide planes under our scored ADPO framework and CIA severity matrix, we identify fundamental cybernetic system challenges. Modern cloud security cannot be achieved via static isolation; instead, cloud platforms must be secured as complex adaptive systems.

Swapnil Baviskar et al.: Preprint submitted to Elsevier

Representative Attack Vector QEMU hardware emulation buffer overflow. Shared virtual switch ARP/IP flow spoofing. Last Level Cache (LLC) Flush+Reload monitoring. Misconfigured mount points or Dirty COW kernel exploit. Leaked API secrets or backdoored dependency packages. TCP SYN flood / auto-scaling loop manipulation.

5.1. Closed-Loop Control Loops and Dynamic Hardware Isolation The primary vulnerability of VM-level boundaries (escape, hopping, side-channels) is the rigid, open-loop design of traditional hypervisors. Defensive efforts (e.g., Intel CATalyst, SMM separation) provide static state guarantees but fail to act as closed-loop, adaptive controllers. When a timing covert channel or microarchitectural cache timing loop operates, the system has no dynamic feedback loop to adjust scheduling frequency or permit dynamic cache permit variations dynamically. Future virtualization control planes must function as closed-loop controllers, where runtime telemetry feeds back into dynamic schedulers. This cybernetic feedback is crucial to adjust CPU resource pacing under anomalous cache timing profiles. This mitigates system entropy (attacks) without requiring processor-specific hardware lockouts.

5.2. Entropy Propagation and Software-Layer Detection Limits Containerization represents a highly nested, sharedkernel control problem where vulnerability propagation in container images functions as an upstream supply-chain entropy vector. Because containers lack physical boundary controls, an exploit in the shared kernel (e.g., Dirty COW) can act as an error state amplifier, immediately collapsing the host OS namespace control loops. While ML-based runtime IDS (e.g., graph-based syscall monitors) show high detection accuracy (A: 3), they suffer from severe operational overhead (O: 1) or high false alarm rates because they lack context-aware feedback loops. Furthermore, supervised ML models suffer from dataset bottlenecks, trained on static traces that fail to represent the dynamic entropy of multitenant, cloud-native deployments. Resolving this requires self-supervised anomaly loops that continuously learn host state variables under normal system operational equilibrium.

5.3. Resilient Feedback Loops and Elastic Saturation Mitigation Distributed Denial of Service (DDoS) and EDoS threats represent a destructive volumetric saturation of cloud resources, exploiting elastic auto-scaling policies to drain monetary budgets. This Yo-Yo effect acts as a positive

Page 13 of 19

From Hypervisor to Container: A Survey of Cloud Security

feedback loop, where attack spikes trigger resource autoscaling, amplifying operational costs instead of maintaining system equilibrium. SDN-driven controllers (e.g., FlowGuard, NIMBUS) attempt to implement dynamic rerouting, but their centralized design introduces control-plane latency. The open challenge lies in edge-deployed, line-rate scrubbing controllers (utilizing eBPF/XDP) that act as distributed closed-loop packet filters, neutralizing attack entropy at the data-plane ingress before volumetric cascades saturate the cloud control plane.

6. Conclusion This survey reframes multi-tenant cloud security through a cybernetic, systems-theoretic lens, analyzing security mechanisms as closed-loop controllers designed to mitigate attack entropy across traditional virtualization and containerization abstractions. By establishing the scored ADPO maturity framework, we converted qualitative literature comparisons into uniform, quantitative metrics, assessing detection accuracy, deployment complexity, performance preservation, and operational overhead. Our analysis reveals that while hypervisor-level controls (e.g., SMM and CATalyst) offer robust hardware-enforced isolation, they lack the adaptive feedback loops necessary to mitigate dynamic timing covert channels. Conversely, software-based container defenses are agile but remain bottlenecked by the absence of high-fidelity, representative dataset feedback loops. The systematic mapping of cloud exploits onto our quantitative CIA severity matrix demonstrates that nesting virtualization boundaries requires stack-wide, coordinated control systems. Future research must move away from static, point-solution defenses. Next-generation cloud architectures must prioritize the engineering of adaptive feedback loops that utilize lightweight, out-of-band monitoring to dynamically maintain system operational equilibrium under volumetric, microarchitectural, or software-layer stress.

Author Contributions Swapnil Baviskar: Developed the core concept, designed the methodology, performed the primary literature analysis, and drafted the original manuscript. Sanoj R: Provided direct supervision during the research phase, reviewed the initial findings, and contributed significant critical revisions to the text. Hiran V Nath: Oversaw project administration, provided high-level supervision and guidance throughout the study, and conducted the final critical review of the paper. All authors discussed the findings, contributed to the intellectual content, and approved the final version of the manuscript for publication. The authors agree to be accountable for all aspects of the work to ensure its accuracy and integrity.

Swapnil Baviskar et al.: Preprint submitted to Elsevier

References [1] M. Pearce, S. Zeadally, R. Hunt, Virtualization: Issues, security threats, and solutions, ACM Comput. Surv. 45 (2) (mar 2013). doi: 10.1145/2431211.2431216. URL https://doi.org/10.1145/2431211.2431216 [2] Y. Shoaib, O. Das, Pouring cloud virtualization security inside out (2014). arXiv:1411.3771. [3] S. Anwar, Z. Inayat, M. F. Zolkipli, J. M. Zain, A. Gani, N. B. Anuar, M. K. Khan, V. Chang, Cross-vm cache-based side channel attacks and proposed prevention mechanisms: A survey, Journal of Network and Computer Applications 93 (2017) 259–279. doi:https://doi.org/10.1016/j.jnca.2017.06.001. URL https://www.sciencedirect.com/science/article/pii/ S1084804517302205

[4] S. Das, J. Werner, M. Antonakakis, M. Polychronakis, F. Monrose, Sok: The challenges, pitfalls, and perils of using hardware performance counters for security, 2019 IEEE Symposium on Security and Privacy (SP) (2019) 20–38. URL https://api.semanticscholar.org/CorpusID:52951646 [5] A. M.A, Jaidhar.C.D, Hypervisor and virtual machine dependent intrusion detection and prevention system for virtualized cloud environment, 2015. doi:10.1109/TAFGEN.2015.7289570. [6] F. Sierra-Arriaga, R. Branco, B. Lee, Security issues and challenges for virtualization technologies, ACM Comput. Surv. 53 (2) (may 2020). doi:10.1145/3382190. URL https://doi.org/10.1145/3382190 [7] A. R. Riddle, S. M. Chung, A survey on the security of hypervisors in cloud computing, in: 2015 IEEE 35th International Conference on Distributed Computing Systems Workshops, 2015, pp. 100–104. doi:10.1109/ICDCSW.2015.28. [8] O. Alkadi, N. Moustafa, B. Turnbull, A review of intrusion detection and blockchain applications in the cloud: Approaches, challenges and solutions, IEEE Access 8 (2020) 104893–104917. doi:10.1109/ ACCESS.2020.2999715. [9] S. Iqbal, M. L. Mat Kiah, B. Dhaghighi, M. Hussain, S. Khan, M. K. Khan, K.-K. Raymond Choo, On cloud security attacks: A taxonomy and intrusion detection and prevention as a service, Journal of Network and Computer Applications 74 (2016) 98–120. doi:https://doi.org/10.1016/j.jnca.2016.08.016. URL https://www.sciencedirect.com/science/article/pii/ S1084804516301771

[10] M. S. Dildar, N. Khan, J. B. Abdullah, A. S. Khan, Effective way to defend the hypervisor attacks in cloud computing, in: 2017 2nd International Conference on Anti-Cyber Crimes (ICACC), 2017, pp. 154–159. doi:10.1109/Anti-Cybercrime.2017.7905282. [11] L. Kwiat, C. A. Kamhoua, K. A. Kwiat, J. Tang, A. Martin, Securityaware virtual machine allocation in the cloud: A game theoretic approach, in: 2015 IEEE 8th International Conference on Cloud Computing, 2015, pp. 556–563. doi:10.1109/CLOUD.2015.80. [12] J. Jabez, B. Muthukumar, Intrusion detection system (ids): Anomaly detection using outlier detection approach, Procedia Computer Science 48 (2015) 338–346, international Conference on Computer, Communication and Convergence (ICCC 2015). doi:https://doi.org/10.1016/j.procs.2015.04.191. URL https://www.sciencedirect.com/science/article/pii/ S1877050915007000

[13] W.-C. Lin, S.-W. Ke, C.-F. Tsai, Cann: An intrusion detection system based on combining cluster centers and nearest neighbors, Knowledge-Based Systems 78 (2015) 13–21. doi:https://doi.org/10.1016/j.knosys.2015.01.009. URL https://www.sciencedirect.com/science/article/pii/ S0950705115000167

[14] M. Alazab, A. Awajan, A. Obeidat, N. Faruqui, A. Bere, S. Ali, W. Wei, Adaptive protocols for hypervisor security in cloud infrastructure using federated learning-based anomaly detection, Engineering Applications of Artificial Intelligence 152 (2025) 110750. doi:https://doi.org/10.1016/j.engappai.2025.110750. URL https://www.sciencedirect.com/science/article/pii/

Page 14 of 19

From Hypervisor to Container: A Survey of Cloud Security S095219762500750X

[15] K. Lazri, S. Laniepce, J. Ben-Othman, Reconsidering intrusion monitoring requirements in shared cloud platforms, in: 2013 International Conference on Availability, Reliability and Security, 2013, pp. 630–637. doi:10.1109/ARES.2013.83. [16] T. Tafazzoli, H. Gharaee Garakani, Security operation center implementation on openstack, in: 2016 8th International Symposium on Telecommunications (IST), 2016, pp. 766–770. doi:10.1109/ISTEL. 2016.7881927. [17] D. Buch, H. Bhatt, Trinetra: a solution to handle cross-vm timedriven attack, SN Applied Sciences 2 (04 2020). doi:10.1007/ s42452-020-2297-z. [18] N. Rakotondravony, B. Taubmann, W. Mandarawi, E. Weishäupl, P. Xu, B. Kolosnjaji, M. Protsenko, H. Meer, H. Reiser, Classifying malware attacks in iaas cloud environments, Journal of Cloud Computing 6 (12 2017). doi:10.1186/s13677-017-0098-8. [19] F. Sabahi, Secure virtualization for cloud environment using hypervisor-based technology, International Journal of Machine Learning and Computing (2012) 39–45. URL https://api.semanticscholar.org/CorpusID:5139882 [20] G. Pan, X. Lin, X. Zhang, Y. Jia, S. Ji, C. Wu, X. Ying, J. Wang, Y. Wu, V-shuttle: Scalable and semantics-aware hypervisor virtual device fuzzing, in: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, CCS ’21, Association for Computing Machinery, New York, NY, USA, 2021, p. 2197–2213. doi:10.1145/3460120.3484811. URL https://doi.org/10.1145/3460120.3484811 [21] G. Zhu, Y. Yin, R. Cai, K. Li, Detecting virtualization specific vulnerabilities in cloud computing environment, in: 2017 IEEE 10th International Conference on Cloud Computing (CLOUD), 2017, pp. 743–748. doi:10.1109/CLOUD.2017.105. [22] W. Fan, W. Huang, Elevated penetration attack models of virtual machine escape based on fsm, EAI Endorsed Transactions on Security and Safety 8 (27) (2021) e3. doi:10.4108/eai.21-7-2021.170555. URL https://publications.eai.eu/index.php/sesa/article/view/40 [23] A. K. Alnaim, A. M. Alwakeel, E. B. Fernández, A misuse pattern for compromising vms via virtual machine escape in nfv, Proceedings of the 14th International Conference on Availability, Reliability and Security (2019). URL https://api.semanticscholar.org/CorpusID:199527268 [24] J. Wu, Z. Lei, S. Chen, W. Shen, An access control model for preventing virtual machine escape attack, Future Internet 9 (2017) 20. URL https://api.semanticscholar.org/CorpusID:32064276 [25] A. Kapravelos, M. Cova, C. Kruegel, G. Vigna, Escape from monkey island: Evading high-interaction honeyclients, in: T. Holz, H. Bos (Eds.), Detection of Intrusions and Malware, and Vulnerability Assessment, Springer Berlin Heidelberg, Berlin, Heidelberg, 2011, pp. 124–143. [26] S. Jin, J. Ahn, J. Seol, S. Cha, J. Huh, S. Maeng, H-svm: Hardwareassisted secure virtual machines under a vulnerable hypervisor, IEEE Transactions on Computers 64 (10) (2015) 2833–2846. doi: 10.1109/TC.2015.2389792. [27] R. Mangalagowri, R. Venkataraman, Hypervisor attack detection using advanced encryption standard (hadaes) algorithm on cloud data, International Journal of Computer Networks and Applications (2022). URL https://api.semanticscholar.org/CorpusID:253264312 [28] D. Gonzales, J. M. Kaplan, E. Saltzman, Z. Winkelman, D. Woods, Cloud-trust—a security assessment model for infrastructure as a service (iaas) clouds, IEEE Transactions on Cloud Computing 5 (3) (2017) 523–536. doi:10.1109/TCC.2015.2415794. [29] D. Sgandurra, E. Lupu, Evolution of attacks, threat models, and solutions for virtualized systems, ACM Comput. Surv. 48 (3) (feb 2016). doi:10.1145/2856126. URL https://doi.org/10.1145/2856126 [30] I. Journal, A novel vm hardening policy for enhancing vm security under cross-virtualization platform (Aug 2021).

Swapnil Baviskar et al.: Preprint submitted to Elsevier

URL

https://www.academia.edu/50774802/IRJET_A_Novel_VM_ Hardening_Policy_for_Enhancing_VM_Security_Under_Cross_ Virtualization_Platform

[31] D. Tank, A. Aggarwal, N. CHAUBEY, Virtualization vulnerabilities, security issues, and solutions: a critical study and comparison, International Journal of Information Technology 14 (02 2019). doi: 10.1007/s41870-019-00294-x. [32] H. Abusaimeh, Virtual machine escape in cloud computing services, International Journal of Advanced Computer Science and Applications 11 (2020). URL https://api.semanticscholar.org/CorpusID:221375325 [33] M. H. Parekh, R. Sridaran, An analysis of security challenges in cloud computing, International Journal of Advanced Computer Science and Applications 4 (2013). URL https://api.semanticscholar.org/CorpusID:15732919 [34] H.-Y. Tsai, M. Siebenhaar, A. Miede, Y. Huang, R. Steinmetz, Threat as a service? virtualization’s impact on cloud security, IT Professional 14 (2012) 32–37. doi:10.1109/MITP.2011.117. [35] N. Almutairy, K. Al-Shqeerat, A survey on security challenges of virtualization technology in cloud computing, International Journal of Computer Science and Information Technology 11 (2019) 95– 105. doi:10.5121/ijcsit.2019.11308. [36] S. Basu, A. Bardhan, K. Gupta, P. Saha, M. Pal, M. Bose, K. Basu, S. Chaudhury, P. Sarkar, Cloud computing security challenges & solutions-a survey, in: 2018 IEEE 8th Annual Computing and Communication Workshop and Conference (CCWC), 2018, pp. 347–356. doi:10.1109/CCWC.2018.8301700. [37] C. F. Cheang, Y. Wang, Z. Cai, G. Xu, Multi-vms intrusion detection for cloud security using dempster-shafer theory, Computers, Materials & Continua 57 (2018) 297–306. doi:10.32604/cmc.2018.03808. [38] O. Alkadi, N. Moustafa, B. Turnbull, A Collaborative Intrusion Detection System Using Deep Blockchain Framework for Securing Cloud Networks, 2021, pp. 553–565. doi:10.1007/ 978-3-030-55180-3_41. [39] N. Chuka-Maduji, V. Anu, Cloud computing security challenges and related defensive measures: A survey and taxonomy, SN Computer Science 2 (07 2021). doi:10.1007/s42979-021-00732-3. [40] K. Benzidane, S. Khoudali, F. Leila, A. Sekkaki, Toward inter-vm visibility in a cloud environment using packet inspection, in: ICT 2013, 2013, pp. 1–5. doi:10.1109/ICTEL.2013.6632122. [41] K. Benzidane, S. Khoudali, A. Sekkaki, Secured architecture for inter-vm traffic in a cloud environment, in: 2nd IEEE Latin American Conference on Cloud Computing and Communications, 2013, pp. 23–28. doi:10.1109/LatinCloud.2013.6842218. [42] Y. Han, J. Chan, T. Alpcan, C. Leckie, Using virtual machine allocation policies to defend against co-resident attacks in cloud computing, IEEE Transactions on Dependable and Secure Computing 14 (1) (2017) 95–108. doi:10.1109/TDSC.2015.2429132. [43] m. kashkoush, M. Azab, M. Eltoweissy, G. Attiya, Towards online smart disguise: Real-time diversification evading co-residency based cloud attacks, in: 2017 IEEE 3rd International Conference on Collaboration and Internet Computing (CIC), 2017, pp. 235–242. doi:10.1109/CIC.2017.00039. [44] G. Ouffoué, A. M. Ortiz, A. R. Cavalli, W. Mallouli, J. DomingoFerrer, D. Sánchez, F. Zaidi, Intrusion detection and attack tolerance for cloud environments: The clarus approach, in: 2016 IEEE 36th International Conference on Distributed Computing Systems Workshops (ICDCSW), 2016, pp. 61–66. doi:10.1109/ICDCSW.2016.27. [45] J. Singh, A. Refaey, A. Shami, Multilevel security framework for nfv based on software defined perimeter, IEEE Network 34 (5) (2020) 114–119. doi:10.1109/MNET.011.1900563. [46] A. Litchfield, A. Shahzad, Virtualization technology: Cross-vm cache side channel attacks make it vulnerable (06 2016). [47] J. Kong, O. Aciicmez, J.-P. Seifert, H. Zhou, Hardware-software integrated approaches to defend against software cache-based side channel attacks, in: 2009 IEEE 15th International Symposium on High Performance Computer Architecture, 2009, pp. 393–404. doi: 10.1109/HPCA.2009.4798277.

Page 15 of 19

From Hypervisor to Container: A Survey of Cloud Security [48] F. Liu, H. Wu, K. Mai, R. B. Lee, Newcache: Secure cache architecture thwarting cache side-channel attacks, IEEE Micro 36 (5) (2016) 8–16. doi:10.1109/MM.2016.85. [49] T. Kim, M. Peinado, G. Mainar-Ruiz, STEALTHMEM: SystemLevel Protection Against Cache-Based Side Channel Attacks in the Cloud, in: USENIX Security Symposium, 2012. URL https://api.semanticscholar.org/CorpusID:7391988 [50] F. Liu, Q. Ge, Y. Yarom, F. Mckeen, C. Rozas, G. Heiser, R. B. Lee, Catalyst: Defeating last-level cache side channel attacks in cloud computing, in: 2016 IEEE International Symposium on High Performance Computer Architecture (HPCA), 2016, pp. 406–418. doi:10.1109/HPCA.2016.7446082. [51] S. Chen, F. Liu, Z. Mi, Y. Zhang, R. B. Lee, H. Chen, X. Wang, Leveraging hardware transactional memory for cache side-channel defenses, in: Proceedings of the 2018 on Asia Conference on Computer and Communications Security, ASIACCS ’18, Association for Computing Machinery, New York, NY, USA, 2018, p. 601–608. doi:10.1145/3196494.3196501. URL https://doi.org/10.1145/3196494.3196501 [52] S. Bandara, M. A. Kinsy, Adaptive caches as a defense mechanism against cache side-channel attacks, Journal of Cryptographic Engineering 11 (3) (2021) 239–255. [53] H. Wang, H. Sayadi, T. Mohsenin, L. Zhao, A. Sasan, S. Rafatirad, H. Homayoun, Mitigating cache-based side-channel attacks through randomization: A comprehensive system and architecture level analysis, in: 2020 Design, Automation & Test in Europe Conference & Exhibition (DATE), 2020, pp. 1414–1419. doi:10.23919/DATE48585. 2020.9116340. [54] L. Liu, A. Wang, W. Zang, M. Yu, M. Xiao, S. Chen, Shuffler: Mitigate cross-vm side-channel attacks via hypervisor scheduling, in: Security and Privacy in Communication Networks, 2018. URL https://api.semanticscholar.org/CorpusID:57764655 [55] M. Sabbagh, Y. Fei, T. Wahl, A. A. Ding, Scadet: A side-channel attack detection tool for tracking prime-probe, in: 2018 IEEE/ACM International Conference on Computer-Aided Design (ICCAD), 2018, pp. 1–8. doi:10.1145/3240765.3240844. [56] S. Yu, X. Gui, J. Lin, An approach with two-stage mode to detect cache-based side channel attacks, in: The International Conference on Information Networking 2013 (ICOIN), 2013, pp. 186–191. doi: 10.1109/ICOIN.2013.6496374. [57] S. Briongos, G. Irazoqui, P. Malagón, T. Eisenbarth, Cacheshield: Detecting cache attacks through self-observation, in: Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy, CODASPY ’18, Association for Computing Machinery, New York, NY, USA, 2018, p. 224–235. doi:10.1145/3176258. 3176320. URL https://doi.org/10.1145/3176258.3176320 [58] T. Zhang, Y. Zhang, R. B. Lee, Cloudradar: A real-time sidechannel attack detection system in clouds, in: F. Monrose, M. Dacier, G. Blanc, J. Garcia-Alfaro (Eds.), Research in Attacks, Intrusions, and Defenses, Springer International Publishing, Cham, 2016, pp. 118–140. [59] M. Mushtaq, A. Akram, M. K. Bhatti, M. Chaudhry, V. Lapotre, G. Gogniat, Nights-watch: a cache-based side-channel intrusion detector using hardware performance counters, in: Proceedings of the 7th International Workshop on Hardware and Architectural Support for Security and Privacy, HASP ’18, Association for Computing Machinery, New York, NY, USA, 2018. doi:10.1145/3214292.3214293. URL https://doi.org/10.1145/3214292.3214293 [60] A. W. Paundu, D. Fall, D. Miyamoto, Y. Kadobayashi, Leveraging kvm events to detect cache-based side channel attacks in a virtualization environment, Secur. Commun. Networks 2018 (2018) 4216240:1–4216240:18. URL https://api.semanticscholar.org/CorpusID:3811410 [61] C. L. Reddy, K. Malathi, Revolutionary hybrid ensembled deep learning model for accurate and robust side-channel attack detection in cloud computing, Scientific Reports 15 (1) (Sep 2025). doi: 10.1038/s41598-025-89794-4.

Swapnil Baviskar et al.: Preprint submitted to Elsevier

[62] G. Sangeetha, G. N. Sumathi, An optimistic technique to detect Cache based Side Channel attacks in Cloud, Peer-to-Peer Networking and Applications 14 (2020) 2473–2486. URL https://api.semanticscholar.org/CorpusID:225264446 [63] B. S. Ainapure, A Novel Approach to Prevent Cloud Infrastructure against Cache Attacks, 2021. URL https://api.semanticscholar.org/CorpusID:235351806 [64] M. Chouhan, H. Hasbullah, Adaptive detection technique for cachebased side channel attack using bloom filter for secure cloud, in: 2016 3rd International Conference on Computer and Information Sciences (ICCOINS), 2016, pp. 293–297. doi:10.1109/ICCOINS. 2016.7783230. [65] Y. Kulah, B. Dincer, C. Yilmaz, E. Savas, SpyDetector: An approach for detecting side-channel attacks at runtime, International Journal of Information Security 18 (08 2019). doi:10.1007/s10207-018-0411-7. [66] M. Godfrey, M. Zulkernine, A server-side solution to cache-based side-channel attacks in the cloud, in: 2013 IEEE Sixth International Conference on Cloud Computing, 2013, pp. 163–170. doi:10.1109/ CLOUD.2013.21. [67] S. Yu, X. Gui, J. Lin, An approach with two-stage mode to detect cache-based side channel attacks, The International Conference on Information Networking 2013 (ICOIN) (2013) 186–191. URL https://api.semanticscholar.org/CorpusID:16117350 [68] J. Shi, P. Kuang, Y. Wang, Y. Yang, A two-stage out-of-box method for detecting side-channel attacks in cloud computing, in: 2022 6th International Conference on Cryptography, Security and Privacy (CSP), 2022, pp. 148–153. doi:10.1109/CSP55486.2022.00035. [69] Y. Wu, L. Lei, Y. Wang, K. Sun, J. Meng, Evaluation on the security of commercial cloud container services, in: W. Susilo, R. H. Deng, F. Guo, Y. Li, R. Intan (Eds.), Information Security, Springer International Publishing, Cham, 2020, pp. 160–177. [70] M. Mattetti, A. Shulman-Peleg, Y. Allouche, A. Corradi, S. Dolev, L. Foschini, Securing the infrastructure and the workloads of linux containers, 2015 IEEE Conference on Communications and Network Security (CNS) (2015) 559–567. URL https://api.semanticscholar.org/CorpusID:17921796 [71] S. Barlev, Z. Basil, S. Kohanim, R. Peleg, S. Regev, A. ShulmanPeleg, Secure yet usable: Protecting servers and linux containers, IBM J. Res. Dev. 60 (2016) 12. URL https://api.semanticscholar.org/CorpusID:207641582 [72] L. Zhang, R. Cushing, C. d. Laat, P. Grosso, A real-time intrusion detection system based on oc-svm for containerized applications, in: 2021 IEEE 24th International Conference on Computational Science and Engineering (CSE), 2021, pp. 138–145. doi:10.1109/CSE53436. 2021.00029. [73] A. El Khairi, M. Caselli, C. Knierim, A. Peter, A. Continella, Contextualizing system calls in containers for anomaly-based intrusion detection, 2022, pp. 9–21. doi:10.1145/3560810.3564266. [74] P. Cui, D. Umphress, Towards unsupervised introspection of containerized application, in: Proceedings of the 2020 10th International Conference on Communication and Network Security, ICCNS ’20, Association for Computing Machinery, New York, NY, USA, 2021, p. 42–51. doi:10.1145/3442520.3442530. URL https://doi.org/10.1145/3442520.3442530 [75] V. V. Sarkale, P. Rad, W. Lee, Secure cloud container: Runtime behavior monitoring using most privileged container (mpc), in: 2017 IEEE 4th International Conference on Cyber Security and Cloud Computing (CSCloud), 2017, pp. 351–356. doi:10.1109/CSCloud. 2017.68. [76] H. Gantikow, C. Reich, M. Knahl, N. Clarke, Rule-based security monitoring of containerized workloads, in: International Conference on Cloud Computing and Services Science, 2019. URL https://api.semanticscholar.org/CorpusID:174799633 [77] S. Srinivasan, A. Kumar, M. Mahajan, D. Sitaram, S. Gupta, Probabilistic real-time intrusion detection system for docker containers, in: S. M. Thampi, S. Madria, G. Wang, D. B. Rawat, J. M. Alcaraz Calero (Eds.), Security in Computing and Communications, Springer Singapore, Singapore, 2019, pp. 336–347.

Page 16 of 19

From Hypervisor to Container: A Survey of Cloud Security [78] O. Tunde-Onadele, J. He, T. Dai, X. Gu, A study on container vulnerability exploit detection, in: 2019 IEEE International Conference on Cloud Engineering (IC2E), 2019, pp. 121–127. doi:10.1109/IC2E. 2019.00026. [79] X. Merino Aguilera, C. Otero, M. Ridley, D. Elliott, Managed containers: A framework for resilient containerized mission critical systems, in: 2018 IEEE 11th International Conference on Cloud Computing (CLOUD), 2018, pp. 946–949. doi:10.1109/CLOUD.2018. 00142. [80] T. Madi, P. Esteves-Verissimo, A fault and intrusion tolerance framework for containerized environments: A specification-based error detection approach, in: 2022 International Workshop on Secure and Reliable Microservices and Containers (SRMC), 2022, pp. 1–8. doi: 10.1109/SRMC57347.2022.00005. [81] X. Wang, Q. Shen, W. Luo, P. Wu, Rsds: Getting system call whitelist for container through dynamic and static analysis, 2020 IEEE 13th International Conference on Cloud Computing (CLOUD) (2020) 600–608. URL https://api.semanticscholar.org/CorpusID:229357778 [82] J. Flora, N. Antunes, Studying the applicability of intrusion detection to multi-tenant container environments, in: 2019 15th European Dependable Computing Conference (EDCC), 2019, pp. 133–136. doi:10.1109/EDCC.2019.00033. [83] L. Lei, J. Sun, K. Sun, C. Shenefiel, R. Ma, Y. Wang, Q. Li, Speaker: Split-phase execution of application containers, in: International Conference on Detection of intrusions and malware, and vulnerability assessment, 2017. URL https://api.semanticscholar.org/CorpusID:20448694 [84] Z. Wan, D. Lo, X. Xia, L. Cai, Practical and effective sandboxing for linux containers, Empirical Software Engineering 24 (2019) 4034 – 4070. URL https://api.semanticscholar.org/CorpusID:195796014 [85] S. Ghavamnia, T. Palit, A. Benameur, M. Polychronakis, Confine: Automated system call policy generation for container attack surface reduction, in: International Symposium on Recent Advances in Intrusion Detection, 2020. URL https://api.semanticscholar.org/CorpusID:220778345 [86] C. Jelesnianski, M. Ismail, Y. Jang, D. Williams, C. Min, Protect the system call, protect (most of) the world with bastion, Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 3 (2023). URL https://api.semanticscholar.org/CorpusID:257632847 [87] M. V. Le, S. Ahmed, D. Williams, H. Jamjoom, Securing containerbased clouds with syscall-aware scheduling, Proceedings of the 2023 ACM Asia Conference on Computer and Communications Security (2023). URL https://api.semanticscholar.org/CorpusID:259328003 [88] S. Jang, S. Song, B. Tak, S. Suneja, M. V. Le, C. Yue, D. Williams, Secquant: Quantifying container system call exposure, in: European Symposium on Research in Computer Security, 2022. URL https://api.semanticscholar.org/CorpusID:252036200 [89] S. Song, S. Suneja, M. V. Le, B. Tak, Sequence-based system call filtering for enhanced container security, is it beneficial?, 2023 IEEE/ACM 23rd International Symposium on Cluster, Cloud and Internet Computing Workshops (CCGridW) (2023) 278–280. URL https://api.semanticscholar.org/CorpusID:259978751 [90] K. Wu, D. Yang, X. Gao, W. Yang, M. Li, D. Wang, Process based container escape monitoring and resource isolation scheme, in: 2022 13th International Conference on Information and Communication Systems (ICICS), 2022, pp. 54–58. doi:10.1109/ICICS55353.2022. 9811204. [91] M. Abubakar, A. Ahmad, P. Fonseca, D. Xu, Shard: Fine-grained kernel specialization with context-aware hardening, in: USENIX Security Symposium, 2021. URL https://api.semanticscholar.org/CorpusID:224441198 [92] S. Kim, B. J. Kim, D. H. Lee, Prof-gen: Practical study on system call whitelist generation for container attack surface reduction, 2021 IEEE 14th International Conference on Cloud Computing (CLOUD)

Swapnil Baviskar et al.: Preprint submitted to Elsevier

(2021) 278–287. URL https://api.semanticscholar.org/CorpusID:243896277 [93] Y. Xing, J. Cao, X. Wang, S. Torabi, K. Sun, F. Yan, Q. Li, Syscap: Profiling and crosschecking syscall and capability configurations for docker images, 2022 IEEE Conference on Communications and Network Security (CNS) (2022) 236–244. URL https://api.semanticscholar.org/CorpusID:253629552 [94] N. Lopes, R. Martins, M. E. Correia, S. Serrano, F. J. B. Nunes, Container hardening through automated seccomp profiling, Proceedings of the 2020 6th International Workshop on Container Technologies and Container Clouds (2020). URL https://api.semanticscholar.org/CorpusID:231579176 [95] X. Gao, Z. Gu, Z. Li, H. Jamjoom, C. Wang, Houdini’s escape: Breaking the resource rein of linux control groups, in: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, CCS ’19, Association for Computing Machinery, New York, NY, USA, 2019, p. 1073–1086. doi:10.1145/3319535. 3354227. URL https://doi.org/10.1145/3319535.3354227 [96] M. Reeves, D. J. Tian, A. Bianchi, Z. B. Celik, Towards improving container security by preventing runtime escapes, in: 2021 IEEE Secure Development Conference (SecDev), 2021, pp. 38–46. doi: 10.1109/SecDev51306.2021.00022. [97] X. Lin, L. Lei, Y. Wang, J. Jing, K. Sun, Q. Zhou, A measurement study on linux container security: Attacks and countermeasures, in: Proceedings of the 34th Annual Computer Security Applications Conference, ACSAC ’18, Association for Computing Machinery, New York, NY, USA, 2018, p. 418–429. doi:10.1145/3274694. 3274720. URL https://doi.org/10.1145/3274694.3274720 [98] Z. Jian, L. Chen, A defense method against docker escape attack, in: Proceedings of the 2017 International Conference on Cryptography, Security and Privacy, ICCSP ’17, Association for Computing Machinery, New York, NY, USA, 2017, p. 142–146. doi:10.1145/ 3058060.3058085. URL https://doi.org/10.1145/3058060.3058085 [99] M. Abbas, S. Khan, A. Monum, F. Zaffar, R. Tahir, D. Eyers, H. Irshad, A. Gehani, V. Yegneswaran, T. Pasquier, Paced: Provenancebased automated container escape detection, in: 2022 IEEE International Conference on Cloud Engineering (IC2E), 2022, pp. 261–272. doi:10.1109/IC2E55432.2022.00035. [100] K.-C. Wang, W. Cheng, J. Zhang, M. Sun, K. Sakai, W.-S. Ku, Honeycontainer: Container-based webshell command injection defending and backtracking, 2023 Silicon Valley Cybersecurity Conference (SVCC) (2023) 1–8. URL https://api.semanticscholar.org/CorpusID:259299806 [101] D. Reti, N. Becker, Escape the fake: Introducing simulated containerescapes for honeypots (2021). arXiv:2104.03651. [102] H. Gantikow, C. Reich, M. Knahl, N. Clarke, Rule-based security monitoring of containerized environments, in: D. Ferguson, V. Méndez Muñoz, C. Pahl, M. Helfert (Eds.), Cloud Computing and Services Science, Springer International Publishing, Cham, 2020, pp. 66–86. [103] B. Tak, H. Kim, S. Suneja, C. Isci, P. Kudva, Security analysis of container images using cloud analytics framework, in: International Conference on Web Services, 2018. URL https://api.semanticscholar.org/CorpusID:49312246 [104] S. Kwon, J.-H. Lee, Divds: Docker image vulnerability diagnostic system, IEEE Access 8 (2020) 42666–42673. doi:10.1109/ACCESS. 2020.2976874. [105] P. Doan, S. Jung, Davs: Dockerfile analysis for container image vulnerability scanning, Computers, Materials & Continua 72 (2022) 1699–1711. doi:10.32604/cmc.2022.025096. [106] O. Javed, S. Toor, Understanding the quality of container security vulnerability detection tools (2021). arXiv:2101.03844. [107] S. Berkovich, J. Kam, G. Wurster, Ubcis: Ultimate benchmark for container image scanning, in: CSET @ USENIX Security Symposium, 2020.

Page 17 of 19

From Hypervisor to Container: A Survey of Cloud Security URL https://api.semanticscholar.org/CorpusID:221539857 [108] L. Chen, Y. Xia, Z. Ma, R. Zhao, Y. Wang, Y. Liu, W. Sun, Z. Xue, Seaf: A scalable, efficient, and application-independent framework for container security detection, Journal of Information Security and Applications 71 (2022) 103351. doi:https://doi.org/10.1016/j.jisa.2022.103351. URL https://www.sciencedirect.com/science/article/pii/ S221421262200196X

[109] F. Loukidis-Andreou, I. Giannakopoulos, K. Doka, N. Koziris, Docker-sec: A fully automated container security enhancement mechanism, Vol. 2018-July, 2018, p. 1561 – 1564, cited by: 18. doi:10.1109/ICDCS.2018.00169. URL https://www.scopus.com/inward/record.uri?eid=2-s2. 0-85050995588&doi=10.1109%2fICDCS.2018.00169&partnerID=40& md5=36bfa4026c5a78d37d744048f8f49b53

[110] J. Pinnamaneni, N. S, P. B. Honnavalli, Identifying vulnerabilities in docker image code using ml techniques, 2022 2nd Asian Conference on Innovation in Technology (ASIANCON) (2022) 1–5. URL https://api.semanticscholar.org/CorpusID:252850963 [111] D. Huang, H. Cui, S. Wen, C. Huang, Security analysis and threats detection techniques on docker container, in: 2019 IEEE 5th International Conference on Computer and Communications (ICCC), 2019, pp. 1214–1220. doi:10.1109/ICCC47050.2019.9064441. [112] M. Cavalcanti, P. Inacio, M. Freire, Performance evaluation of container-level anomaly-based intrusion detection systems for multitenant applications using machine learning algorithms, in: Proceedings of the 16th International Conference on Availability, Reliability and Security, ARES 21, Association for Computing Machinery, New York, NY, USA, 2021. doi:10.1145/3465481.3470066. URL https://doi.org/10.1145/3465481.3470066 [113] M. Dahlmanns, C. Sander, R. Decker, K. Wehrle, Secrets revealed in container images: An internet-wide study on occurrence and impact, Proceedings of the 2023 ACM Asia Conference on Computer and Communications Security (2023). URL https://api.semanticscholar.org/CorpusID:259325851 [114] Y. Zheng, W. Dong, J. Zhao, Zerodvs: Trace-ability and security detection of container image based on inheritance graph, in: 2021 IEEE 5th International Conference on Cryptography, Security and Privacy (CSP), 2021, pp. 186–192. doi:10.1109/CSP51677.2021. 9357496. [115] K. Torkura, M. I. H. Sukmana, F. Cheng, C. Meinel, Cavas: Neutralizing application and container security vulnerabilities in the cloud native era, 2018. [116] A. Alsaeedi, O. Bamasag, A. Munshi, Real-time DDoS flood attack monitoring and detection (RT-AMD) model for cloud computing, in: Proceedings of the 4th International Conference on Future Networks and Distributed Systems, ICFNDS ’20, Association for Computing Machinery, New York, NY, USA, 2021. doi:10.1145/3440749. 3442606. URL https://doi.org/10.1145/3440749.3442606 [117] J. Choi, C. Choi, B. Ko, P. Kim, A method of DDoS attack detection using http packet pattern and rule engine in cloud computing environment, Soft Computing 18 (2014) 1697–1703. doi:10.1007/ s00500-014-1250-8. [118] M. Hatef, V. Shaker, R. Jabbarpour, J. Jung, H. Zarrabi, Hidcc: A hybrid intrusion detection approach in cloud computing, Concurrency and Computation: Practice and Experience 30 (2017) e4171. doi:10.1002/cpe.4171. [119] E. Besharati, M. Naderan, E. Namjoo, Lr-hids: Logistic regression host-based intrusion detection system for cloud environments, Journal of Ambient Intelligence and Humanized Computing 10 (2019) 3669–3692. doi:10.1007/s12652-018-1093-8. [120] R. K. Deka, D. K. Bhattacharyya, J. K. Kalita, Active learning to detect DDoS attack using ranked features, Computer Communications 145 (2019) 203–222. doi:https: //doi.org/10.1016/j.comcom.2019.06.010. URL https://www.sciencedirect.com/science/article/pii/

[121] A. R. Yusof, N. I. Udzir, A. Selamat, An evaluation on KNN-SVM algorithm for detection and prediction of DDoS attack, in: International Conference on Industrial, Engineering and Other Applications of Applied Intelligent Systems, 2016. [122] F. Filho, F. Silveira, A. Junior, G. vargas solar, L. Silveira, Smart detection: An online approach for DoS/DDoS attack detection using machine learning, Security and Communication Networks 2019 (2019) 1–15. doi:10.1155/2019/1574749. [123] P. Rivas, C. DeCusatis, M. Oakley, A. Antaki, N. Blaskey, S. LaFalce, S. Stone, Machine learning for DDoS attack classification using hive plots, 2019, pp. 0401–0407. doi:10.1109/ UEMCON47517.2019.8993021. [124] D. Yadlapati, N. Siddhartha, M. Seelamneni, A. Y. Nali, H. R. Sangaraju, P. S. V. S. Sridhar, Security management approaches over the cloud, in: 2023 International Conference on Sustainable Computing and Data Communication Systems (ICSCDS), 2023, pp. 1277–1282. doi:10.1109/ICSCDS56580.2023.10105026. [125] A. Mustapha, R. Khatoun, S. Zeadally, F. Chbib, A. Fadlallah, W. Fahs, A. El Attar, Detecting DDoS attacks using adversarial neural network, Computers & Security 127 (2023) 103117. doi:https://doi.org/10.1016/j.cose.2023.103117. URL https://www.sciencedirect.com/science/article/pii/ S0167404823000275

[126] H. B. Baraka, H. Tianfield, Intrusion detection system for cloud environment, in: Proceedings of the 7th International Conference on Security of Information and Networks, SIN ’14, Association for Computing Machinery, New York, NY, USA, 2014, p. 399–404. doi:10.1145/2659651.2659682. URL https://doi.org/10.1145/2659651.2659682 [127] M. Barati, A. Abdullah, N. I. Udzir, R. Mahmod, N. Mustapha, Distributed denial of service detection using hybrid machine learning technique, in: 2014 International Symposium on Biometrics and Security Technologies (ISBAST), 2014, pp. 268–273. doi:10.1109/ ISBAST.2014.7013133. [128] Y. Jia, F. Zhong, A. Alrawais, B. Gong, X. Cheng, Flowguard: An intelligent edge defense mechanism against iot DDoS attacks, IEEE Internet of Things Journal 7 (10) (2020) 9552–9562. doi:10.1109/ JIOT.2020.2993782. [129] R. Miao, M. Yu, N. Jain, Nimbus: Cloud-scale attack detection and mitigation, in: Proceedings of the 2014 ACM Conference on SIGCOMM, SIGCOMM ’14, Association for Computing Machinery, New York, NY, USA, 2014, p. 121–122. doi:10.1145/2619239. 2631446. URL https://doi.org/10.1145/2619239.2631446 [130] T. Phan, M. Park, Efficient distributed denial-of-service attack defense in sdn-based cloud, IEEE Access PP (2019) 1–1. doi:10.1109/ ACCESS.2019.2896783. [131] A. Aldribi, I. Traore, B. Moa, Data Sources and Datasets for Cloud Intrusion Detection Modeling and Evaluation, Springer International Publishing, Cham, 2018, pp. 333–366. doi:10.1007/ 978-3-319-73676-1_13. URL https://doi.org/10.1007/978-3-319-73676-1_13 [132] Y. Shan, G. Kesidis, D. Fleck, Cloud-side shuffling defenses against DDoS attacks on proxied multiserver systems, in: Proceedings of the 2017 on Cloud Computing Security Workshop, CCSW ’17, Association for Computing Machinery, New York, NY, USA, 2017, p. 1–10. doi:10.1145/3140649.3140650. URL https://doi.org/10.1145/3140649.3140650 [133] A. V. Songa, G. R. Karri, An integrated sdn framework for early detection of ddos attacks in cloud computing, Journal of Cloud Computing 13 (1) (Mar 2024). doi:10.1186/s13677-024-00625-9. [134] S. Q. A. Shah, F. Z. Khan, M. Ahmad, Mitigating tcp syn flooding based edos attack in cloud computing environment using binomial distribution in sdn, Computer Communications 182 (2022) 198–211. doi:https://doi.org/10.1016/j.comcom.2021.11.008. URL https://www.sciencedirect.com/science/article/pii/ S0140366421004357

S0140366419303858

Swapnil Baviskar et al.: Preprint submitted to Elsevier

Page 18 of 19

From Hypervisor to Container: A Survey of Cloud Security [135] B. M. Amro, S. Salah, M. Moreb, A comprehensive architectural framework of moving target defenses against ddos attacks, Journal of Cyber Security and Mobility 12 (04) (2023) 605–628. doi:10.13052/jcsm2245-1439.1248. URL https://journals.riverpublishers.com/index.php/JCSANDM/ article/view/18533

[136] A. Kumar, G. Somani, Service separation assisted ddos attack mitigation in cloud targets, Journal of Information Security and Applications 73 (2023) 103435. doi:https: //doi.org/10.1016/j.jisa.2023.103435. URL https://www.sciencedirect.com/science/article/pii/ S2214212623000200

[137] A. Sadiq, H. J. Syed, A. A. Ansari, A. O. Ibrahim, M. Alohaly, M. Elsadig, Detection of denial of service attack in cloud based kubernetes using ebpf, Applied Sciences 13 (8) (2023). doi:10.3390/ app13084700. URL https://www.mdpi.com/2076-3417/13/8/4700 [138] S. M. Hezavehi, R. Rahmani, Interactive anomaly-based ddos attack detection method in cloud computing environments using a third party auditor, Journal of Parallel and Distributed Computing 178 (2023) 82–99. [139] A. Yudhana, I. Riadi, S. Suharti, Network forensics against volumetric-based distributed denial of service attacks on cloud and the edge computing, International Journal of Safety and Security Engineering 12 (5) (2022) 577–588. doi:10.18280/ijsse.120505. [140] D. Balasubramaniyan, K. Kv, R. Radha, A. Venaik, Iterative dichotomiser posteriori method based service attack detection in cloud computing, Computer Systems Science and Engineering 44 (2022) 1099–1107. doi:10.32604/csse.2023.024691. [141] T. Jaya, Detecting and preventing of attacks in cloud computing using hybrid algorithm, Intelligent Automation & Soft Computing 35 (02 2023). doi:10.32604/iasc.2023.024291. [142] A. Bremler-Barr, E. Brosh, M. Sides, DDoS attack on cloud autoscaling mechanisms, in: IEEE INFOCOM 2017 - IEEE Conference on Computer Communications, 2017, pp. 1–9. doi:10.1109/INFOCOM. 2017.8057010. [143] M. Soltys, Cybersecurity in the AWS cloud, CoRR abs/2003.12905 (2020). arXiv:2003.12905. URL https://arxiv.org/abs/2003.12905 [144] N. J. Mitchell, K. Zunnurhain, Google cloud platform security, in: Proceedings of the 4th ACM/IEEE Symposium on Edge Computing, SEC ’19, Association for Computing Machinery, New York, NY, USA, 2019, p. 319–322. doi:10.1145/3318216.3363371. URL https://doi.org/10.1145/3318216.3363371

Swapnil Baviskar et al.: Preprint submitted to Elsevier

Page 19 of 19

Record · ID 919255 · SHA-256 720d3c64b0c035b5
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.