Hardening Hypervisors with Ombro
Ethan Johnson, Colin Pronovost, John Criswell
Abstract
This paper presents Ombro, a low-level virtual instruction set architecture (vISA) which enforces compiler-based security policies on real-world commodity hypervisors. We extend the Secure Virtual Architecture (which itself extends the LLVM compiler's Intermediate Representation) to support the full set of hardware operations needed to run an x86 commodity hypervisor used in some of the world's largest public clouds, namely, the Xen 4.12 hypervisor, running in full hardwareaccelerated mode using Intel's Virtual Machine Extensions (VMX). We have ported Xen 4.12 to the Ombro vISA and demonstrated that it can run unmodified guest VMs of realworld relevance (namely, Linux guests under Xen's HVM and PVH modes). Furthermore, to demonstrate Ombro's ability to harden hypervisors from attack, Ombro implements control flow integrity and the first protected shadow (split) stack for x86 hypervisors. Our performance results show that Ombro achieves this protection without imposing measurable overheads on most application benchmarks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bd61ef49-76bd-4f07-a5a7-8c80c377f01bBuilds on5
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- Shielding Software From Privileged Side-Channel AttacksXiaowan Dong, Zhuojia Shen, John Criswell, Alan L. Cox et al.USENIX Security 2018 · 45 citations
- Silhouette: Efficient Protected Shadow Stacks for Embedded SystemsJie Zhou, Yufei Du, Zhuojia Shen, Lele Ma et al.USENIX Security 2020
- Holistic Control-Flow Protection on Real-Time Embedded Systems with KageYufei Du, Zhuojia Shen, Komail Dharsee, Jie Zhou et al.USENIX Security 2022
Related papers
- HyperMirage: Direct State Manipulation in Hybrid Virtual CPU FuzzingManuel Andreas, Fabian Specht, Marius MomeuNDSS 2026
- Protecting Cloud Virtual Machines from Hypervisor and Host Operating System ExploitsShih-Wei Li, John S. Koh, Jason NiehUSENIX Security 2019 · 49 citations
- (Mostly) Exitless VM Protection from Untrusted Hypervisor through Disaggregated Nested VirtualizationZeyu Mi, Dingji Li, Haibo Chen, Binyu Zang et al.USENIX Security 2020
- Security and Performance in the Delegated User-level VirtualizationJiahao Chen, Dingji Li, Zeyu Mi, Yuxuan Liu et al.OSDI 2023 · 10 citations
- Deconstructing XenLe Shi, Yuming Wu, Yubin Xia, Nathan Dautenhahn et al.NDSS 2017 · 54 citations
