USENIX ATC2022顶会
Hardening Hypervisors with Ombro
Ethan Johnson, Colin Pronovost, John Criswell
摘要
This paper presents Ombro, a low-level virtual instruction set architecture (vISA) which enforces compiler-based security policies on real-world commodity hypervisors. We extend the Secure Virtual Architecture (which itself extends the LLVM compiler's Intermediate Representation) to support the full set of hardware operations needed to run an x86 commodity hypervisor used in some of the world's largest public clouds, namely, the Xen 4.12 hypervisor, running in full hardwareaccelerated mode using Intel's Virtual Machine Extensions (VMX). We have ported Xen 4.12 to the Ombro vISA and demonstrated that it can run unmodified guest VMs of realworld relevance (namely, Linux guests under Xen's HVM and PVH modes). Furthermore, to demonstrate Ombro's ability to harden hypervisors from attack, Ombro implements control flow integrity and the first protected shadow (split) stack for x86 hypervisors. Our performance results show that Ombro achieves this protection without imposing measurable overheads on most application benchmarks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- Shielding Software From Privileged Side-Channel AttacksXiaowan Dong, Zhuojia Shen, John Criswell, Alan L. Cox 等USENIX Security 2018 · 被引用 45 次
- Silhouette: Efficient Protected Shadow Stacks for Embedded SystemsJie Zhou, Yufei Du, Zhuojia Shen, Lele Ma 等USENIX Security 2020
- Holistic Control-Flow Protection on Real-Time Embedded Systems with KageYufei Du, Zhuojia Shen, Komail Dharsee, Jie Zhou 等USENIX Security 2022
相关 Paper
- HyperMirage: Direct State Manipulation in Hybrid Virtual CPU FuzzingManuel Andreas, Fabian Specht, Marius MomeuNDSS 2026
- Protecting Cloud Virtual Machines from Hypervisor and Host Operating System ExploitsShih-Wei Li, John S. Koh, Jason NiehUSENIX Security 2019 · 被引用 49 次
- (Mostly) Exitless VM Protection from Untrusted Hypervisor through Disaggregated Nested VirtualizationZeyu Mi, Dingji Li, Haibo Chen, Binyu Zang 等USENIX Security 2020
- Security and Performance in the Delegated User-level VirtualizationJiahao Chen, Dingji Li, Zeyu Mi, Yuxuan Liu 等OSDI 2023 · 被引用 10 次
- Deconstructing XenLe Shi, Yuming Wu, Yubin Xia, Nathan Dautenhahn 等NDSS 2017 · 被引用 54 次
