A State-of-the Art Survey on Various Attacks and Security Tools at the Virtualization Layer of Cloud Computing

Aditya Nautiyal, Subhangi Saklani, Preeti Mishra, Satendra Kumar, Harshit Bisht · 2023

With the advent of technologies such as the Internet of Things (IoT), big data analytics, and cloud computing, most businesses have adopted virtualization technologies. Virtualization is a key technology that enables the execution of multiple operating systems in one physical machine, thereby allowing the sharing of resources within the same environment. The pay-per-use and on-demand sharing of resources have increased the utilization of cloud-based services, thereby increasing various security concerns. There are various attacks possible at different cloud computing layers, i.e., application layer, virtualization layer, network layer, hardware layer, etc. In this chapter, we have explored various attacking possibilities and defensive tools, specially focusing on network layer of cloud computing. Various traditional security solutions such as Network Intrusion Prevention System (NIPS) and Network Intrusion Detection System (NIDS) are used by researchers to protect the cloud from network attacks. To effectively secure network layer, these traditional tools are no longer sufficient. One has to relentlessly search for tools that specifically focus on virtualization layer of cloud. Cloud design architecture differs significantly from traditional network design architectures. Moreover, there are different design constraints at different layers of cloud. Therefore, the same tool cannot be deployed at all layers. Hence, it is crucial to classify all the tools according to the layered architecture of cloud. In this chapter, we have discussed different security and attacking tools, providing a detailed study of the tools. Each category is further classified based on the target layer of deployment at the virtualization layer. A case study on “eXplainable Artificial Intelligence based Network Intrusion Detection System” (XAI-NIDS) has been performed using UNSW-NB15 data set to provide the practical demonstration on network attack analysis.

Read the paper · More papers on PaperTik