On the feasibility of software attacks on commodity virtual machine monitors via direct device assignment

On the feasibility of software attacks on commodity virtual machine monitors via direct device assignment
复制标题

DOI:
10.1145/2590296.2590299
复制
发表时间:
2014-06
期刊:
Proceedings of the 9th ACM symposium on Information, computer and communications security
影响因子:
--
通讯作者:
Gábor Pék;A. Lanzi;Abhinav Srivastava;D. Balzarotti;Aurélien Francillon;C. Neumann
Gábor Pék;A. Lanzi;Abhinav Srivastava;D. Balzarotti;Aurélien Francillon;C. Neumann
中科院分区:
其他
文献类型:
--
作者:
Gábor Pék;A. Lanzi;Abhinav Srivastava;D. Balzarotti;Aurélien Francillon;C. Neumann

文献摘要

被引文献

相似文献

虚拟机监视器(VMM)的安全性是一个具有挑战性且积极的研究领域。特别是,由于硬件虚拟化在云解决方案中的重要性越来越大,重要的是要清楚地理解现有的和与VMM相关的威胁。不幸的是,这个主题仍然存在很多困惑,因为过去在实践中从未实施过许多攻击,也没有在现实的情况下进行测试。在本文中,我们通过基于直接分配的设备实施,测试和分类了广泛的已知和未知攻击,从而阐明了相关的威胁和防御措施。我们对详尽的VMM配置进行了这些攻击,以确定它们的潜在影响。我们的实验表明,大多数先前已知的攻击在当前的VMM设置中无效。我们还开发了一种称为PTFUZZ的自动工具,以发现影响当前VMM的硬件级问题。通过使用PTFUZZ,我们发现了几种意外硬件行为的案例,以及在英特尔平台上的主要漏洞,可能会影响野外使用的大量机器。这些漏洞会影响使用直接分配的设备(例如网络卡)并具有所有现有的硬件保护机制的无特权虚拟机。这样的漏洞允许攻击者生成宿主端中断或硬件故障,从而违反了预期的隔离属性。这些可能会导致主机软件(例如VMM)停止,并且可能会为实用的VMM开发打开大门。我们认为,我们的研究可以帮助云提供者和研究人员更好地了解其当前体系结构的局限性,以提供安全的硬件虚拟化并为将来的攻击做准备。
The security of virtual machine monitors (VMMs) is a challenging and active field of research. In particular, due to the increasing significance of hardware virtualization in cloud solutions, it is important to clearly understand existing and arising VMM-related threats. Unfortunately, there is still a lot of confusion around this topic as many attacks presented in the past have never been implemented in practice or tested in a realistic scenario. In this paper, we shed light on VM related threats and defences by implementing, testing, and categorizing a wide range of known and unknown attacks based on directly assigned devices. We executed these attacks on an exhaustive set of VMM configurations to determine their potential impact. Our experiments suggest that most of the previously known attacks are ineffective in current VMM setups. We also developed an automatic tool, called PTFuzz, to discover hardware-level problems that affects current VMMs. By using PTFuzz, we found several cases of unexpected hardware behaviour, and a major vulnerability on Intel platforms that potentially impacts a large set of machines used in the wild. These vulnerabilities affect unprivileged virtual machines that use a directly assigned device (e.g., network card) and have all the existing hardware protection mechanisms enabled. Such vulnerabilities either allow an attacker to generate a host-side interrupt or hardware faults, violating expected isolation properties. These can cause host software (e.g., VMM) halt as well as they might open the door for practical VMM exploitations. We believe that our study can help cloud providers and researchers to better understand the limitations of their current architectures to provide secure hardware virtualization and prepare for future attacks.