Lune

USENIX ATC2022顶会

Hardening Hypervisors with Ombro

Ethan Johnson, Colin Pronovost, John Criswell

出版方
2022年份

摘要

This paper presents Ombro, a low-level virtual instruction set architecture (vISA) which enforces compiler-based security policies on real-world commodity hypervisors. We extend the Secure Virtual Architecture (which itself extends the LLVM compiler's Intermediate Representation) to support the full set of hardware operations needed to run an x86 commodity hypervisor used in some of the world's largest public clouds, namely, the Xen 4.12 hypervisor, running in full hardwareaccelerated mode using Intel's Virtual Machine Extensions (VMX). We have ported Xen 4.12 to the Ombro vISA and demonstrated that it can run unmodified guest VMs of realworld relevance (namely, Linux guests under Xen's HVM and PVH modes). Furthermore, to demonstrate Ombro's ability to harden hypervisors from attack, Ombro implements control flow integrity and the first protected shadow (split) stack for x86 hypervisors. Our performance results show that Ombro achieves this protection without imposing measurable overheads on most application benchmarks.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext bd61ef49-76bd-4f07-a5a7-8c80c377f01b

它引用的顶会 Paper5

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖