Publication:
Assessment of hypervisor vulnerabilities

dc.contributor.authorAmmarit Thongthuaen_US
dc.contributor.authorSudsanguan Ngamsuriyarojen_US
dc.contributor.otherMahidol Universityen_US
dc.date.accessioned2018-12-11T02:27:09Z
dc.date.accessioned2019-03-14T08:04:19Z
dc.date.available2018-12-11T02:27:09Z
dc.date.available2019-03-14T08:04:19Z
dc.date.issued2016-10-18en_US
dc.description.abstract© 2016 IEEE. Hypervisors are the main components for managing virtual machines on cloud computing systems. Thus, the security of hypervisors is very crucial as the whole system could be compromised when just one vulnerability is exploited. In this paper, we assess the vulnerabilities of widely used hypervisors including VMware ESXi, Citrix XenServer and KVM using the NIST 800-115 security testing framework. We perform real experiments to assess the vulnerabilities of those hypervisors using security testing tools. The results are evaluated using weakness information from CWE, and using vulnerability information from CVE. We also compute the severity scores using CVSS information. All vulnerabilities found of three hypervisors will be compared in terms of weaknesses, severity scores and impact. The experimental results showed that ESXi and XenServer have common weaknesses and vulnerabilities whereas KVM has fewer vulnerabilities. In addition, we discover a new vulnerability called HTTP response splitting on ESXi web interface.en_US
dc.identifier.citationProceedings - International Conference on Cloud Computing Research and Innovation 2016, ICCCRI 2016. (2016), 71-77en_US
dc.identifier.doi10.1109/ICCCRI.2016.19en_US
dc.identifier.other2-s2.0-84994879740en_US
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/20.500.14594/43238
dc.rightsMahidol Universityen_US
dc.rights.holderSCOPUSen_US
dc.source.urihttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=84994879740&origin=inwarden_US
dc.subjectBusiness, Management and Accountingen_US
dc.subjectComputer Scienceen_US
dc.titleAssessment of hypervisor vulnerabilitiesen_US
dc.typeConference Paperen_US
dspace.entity.typePublication
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=84994879740&origin=inwarden_US

Files

Collections