DocumentCode :
3662500
Title :
Blind hypervision to protect virtual machine privacy against hypervisor escape vulnerabilities
Author :
P. Dubrulle;R. Sirdey;P. Doré;M. Aichouch;E. Ohayon
Author_Institution :
CEA, LIST, Point Courier 172, FR-91191 Gif-sur-Yvette Cedex, France
fYear :
2015
fDate :
7/1/2015 12:00:00 AM
Firstpage :
1394
Lastpage :
1399
Abstract :
Hypervision is being widely implemented in an effort to control costs and to simplify management through consolidation of servers. It has been recently unraveled that well over a third of virtualization vulnerabilities reside in the hyper-visor, mostly due to hypervisor escape. The exploitation of these vulnerabilities allows an attacker, among other things, to access and/or modify data of other Virtual Machines (VMs) by escaping from its VM and executing malicious code in the hypervisor. This paper introduces the general idea of blind hypervision, a hardware/software co-design to prevent such attackers to access private elements of other VMs. Blind hypervision limits the rights of the hypervisor regarding memory access, so that a malicious agent executing with hypervisor rights cannot access the data of the VMs.
Keywords :
"Virtual machine monitors","Hardware","Memory management","Loading","Software","Registers"
Publisher :
ieee
Conference_Titel :
Industrial Informatics (INDIN), 2015 IEEE 13th International Conference on
ISSN :
1935-4576
Electronic_ISBN :
2378-363X
Type :
conf
DOI :
10.1109/INDIN.2015.7281938
Filename :
7281938
Link To Document :
بازگشت