USENIX Security2019Top-tier venue
Protecting Cloud Virtual Machines from Hypervisor and Host Operating System Exploits
Shih-Wei Li, John S. Koh, Jason Nieh
Abstract
Hypervisors are widely deployed by cloud computing providers to support virtual machines, but their growing complexity poses a security risk as large codebases contain many vulnerabilities. We have created HypSec, a new hypervisor design for retrofitting an existing commodity hypervisor using microkernel principles to reduce its trusted computing base while protecting the confidentiality and integrity of virtual machines. HypSec partitions the hypervisor into an untrusted host that performs most complex hypervisor functionality without access to virtual machine data, and a trusted core that provides access control to virtual machine data and performs basic CPU and memory virtualization. Hardware virtualization support is used to isolate and protect the trusted core and execute it at a higher privilege level so it can mediate virtual machine exceptions and protect VM data in CPU and memory. HypSec takes an end-to-end approach to securing I/O to simplify its design, with applications increasingly using secure network connections in the cloud. We have used HypSec to retrofit KVM, showing how our approach can support a widely-used full-featured hypervisor integrated with a commodity operating system. The implementation has a trusted computing base of only a few thousand lines of code, many orders of magnitude less than KVM. We show that HypSec protects the confidentiality and integrity of virtual machines running unmodified guest operating systems while only incurring modest performance overhead for real application workloads. Bug
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers14
- TwinVisor: Hardware-isolated Confidential Virtual Machines for ARMDingji Li, Zeyu Mi, Yubin Xia, Binyu Zang et al.SOSP 2021 · 39 citations
- A Secret-Free Hypervisor: Rethinking Isolation in the Age of Speculative VulnerabilitiesHongyan Xia, David Zhang, Wei Liu, István Haller et al.S&P 2022 · 18 citations
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang et al.ASPLOS 2023 · 12 citations
- CPC: Flexible, Secure, and Efficient CVM Maintenance with Confidential Procedure CallsJiahao Chen, Zeyu Mi, Yubin Xia, Haibing Guan et al.USENIX ATC 2024 · 11 citations
- Security and Performance in the Delegated User-level VirtualizationJiahao Chen, Dingji Li, Zeyu Mi, Yuxuan Liu et al.OSDI 2023 · 10 citations
Builds on2
Related papers
- A Secure and Formally Verified Linux KVM HypervisorShih-Wei Li, Xupeng Li, Ronghui Gu, Jason Nieh et al.S&P 2021 · 72 citations
- Formally Verified Memory Protection for a Commodity Multiprocessor HypervisorShih-Wei Li, Xupeng Li, Ronghui Gu, Jason Nieh et al.USENIX Security 2021 · 48 citations
- Core slicing: closing the gap between leaky confidential VMs and bare-metal cloudZiqiao Zhou, Yizhou Shan, Weidong Cui, Xinyang Ge et al.OSDI 2023 · 12 citations
- Hardening Hypervisors with OmbroEthan Johnson, Colin Pronovost, John CriswellUSENIX ATC 2022
- BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating SystemsAlexander Van't Hof, Jason NiehOSDI 2022 · 44 citations
