【24h】

Assessment of Hypervisor Vulnerabilities

机译:评估虚拟机管理程序漏洞

获取原文

摘要

Hypervisors are the main components for managing virtual machines on cloud computing systems. Thus, the security of hypervisors is very crucial as the whole system could be compromised when just one vulnerability is exploited. In this paper, we assess the vulnerabilities of widely used hypervisors including VMware ESXi, Citrix XenServer and KVM using the NIST 800-115 security testing framework. We perform real experiments to assess the vulnerabilities of those hypervisors using security testing tools. The results are evaluated using weakness information from CWE, and using vulnerability information from CVE. We also compute the severity scores using CVSS information. All vulnerabilities found of three hypervisors will be compared in terms of weaknesses, severity scores and impact. The experimental results showed that ESXi and XenServer have common weaknesses and vulnerabilities whereas KVM has fewer vulnerabilities. In addition, we discover a new vulnerability called HTTP response splitting on ESXi Web interface.
机译:虚拟机管理程序是用于在云计算系统上管理虚拟机的主要组件。因此,虚拟机管理程序的安全性是非常重要的,因为当仅利用一个漏洞时整个系统可能会受到损害。在本文中,我们使用NIST 800-115安全测试框架评估了VMware ESXi,Citrix XenServer和KVM,包括VMware ESXi,Citrix XenServer和KVM等广泛使用的虚拟机管理程序的漏洞。我们使用安全测试工具执行真实实验以评估这些虚拟机管理程序的漏洞。结果使用来自CWE的弱点信息进行评估,并使用CVE使用漏洞信息。我们还使用CVSS信息计算严重性分数。在弱点,严重程度和影响方面,将比较三种虚拟机制的所有漏洞。实验结果表明,ESXi和Xenserver具有普遍的弱点和漏洞,而KVM具有较少的漏洞。此外,我们发现ESXi Web界面上称为HTTP响应拆分的新漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号