首页> 外文期刊>Computer architecture news >Architectural Support for Hypervisor-Secure Virtualization
【24h】

Architectural Support for Hypervisor-Secure Virtualization

机译:Hypervisor安全虚拟化的架构支持

获取原文
获取原文并翻译 | 示例
           

摘要

Virtualization has become a standard part of many computer systems. A key part of virtualization is the all-powerful hypervisor which manages the physical platform and can access all of its resources, including memory assigned to the guest virtual machines (VMs). Continuing releases of bug reports and exploits in the virtualization software show that defending the hypervisor against attacks is very difficult. In this work, we present hypervisor-secure virtualization - a new research direction with the goal of protecting the guest VMs from an untrusted hypervisor. We also present the HyperWall architecture which achieves hypervisor-secure virtualization, using hardware to provide the protections. HyperWall allows a hypervisor to freely manage the memory, processor cores and other resources of a platform. Yet once VMs are created, our new Confidentiality and Integrity Protection (CIP) tables protect the memory of the guest VMs from accesses by the hypervisor or by DMA, depending on the customer's specification. If a hypervisor does become compromised, e.g. by an attack from a malicious VM, it cannot be used in turn to attack other VMs. The protections are enabled through minimal modifications to the microprocessor and memory management units. Whereas much of the previous work concentrates on protecting the hypervisor from attacks by guest VMs, we tackle the problem of protecting the guest VMs from the hypervisor.
机译:虚拟化已成为许多计算机系统的标准部分。虚拟化的关键部分是功能强大的虚拟机管理程序,它管理物理平台并可以访问其所有资源,包括分配给来宾虚拟机(VM)的内存。持续发布的错误报告和虚拟化软件中的漏洞表明,保护虚拟机监控程序免受攻击非常困难。在这项工作中,我们提出了虚拟机管理程序安全的虚拟化-一种新的研究方向,旨在保护来宾VM不受不受信任的虚拟机管理程序的侵害。我们还介绍了HyperWall体系结构,该体系结构使用硬件提供保护来实现虚拟机管理程序安全的虚拟化。 HyperWall允许管理程序自由管理平台的内存,处理器内核和其他资源。然而,一旦创建了VM,我们新的机密性和完整性保护(CIP)表将根据客户的规范保护来宾VM的内存,使其不受管理程序或DMA的访问。如果系统管理程序确实受到威胁,例如通过来自恶意VM的攻击,它不能依次用于攻击其他VM。通过对微处理器和内存管理单元进行最少的修改即可启用保护。尽管先前的许多工作都集中在保护虚拟机管理程序不受来宾VM的攻击,但我们解决了保护来宾VM不受虚拟机管理程序攻击的问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号