Protecting Cloud Virtual Machines from Hypervisor and Host Operating System Exploits

Protecting Cloud Virtual Machines from Hypervisor and Host Operating System Exploits
复制标题

DOI:
--
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Shih-wei Li;John S. Koh;Jason Nieh
Shih-wei Li;John S. Koh;Jason Nieh
中科院分区:
其他
文献类型:
--
作者:
Shih-wei Li;John S. Koh;Jason Nieh

文献摘要

相似文献

云计算提供商广泛部署虚拟机管理程序来支持虚拟机,但其日益增长的复杂性带来了安全风险,因为大型代码库包含许多漏洞。我们已经创建了HypSec,这是一种新的虚拟机管理程序设计,用于使用微内核原理改造现有的商用虚拟机管理程序,以减少其可信计算基础,同时保护虚拟机的机密性和完整性。HypSec将虚拟机管理程序划分为不受信任的主机和受信任的核心,前者在不访问虚拟机数据的情况下执行最复杂的虚拟机管理程序功能,后者提供对虚拟机数据的访问控制并执行基本的CPU和内存虚拟化。硬件虚拟化支持用于隔离和保护受信任的核心,并以更高的权限级别执行它,以便它可以调解虚拟机异常并保护CPU和内存中的VM数据。HypSec采用端到端的方法来保护I/O,以简化其设计,应用程序越来越多地使用云中的安全网络连接。我们已经使用HypSec来改造KVM,展示了我们的方法如何支持与商用操作系统集成的广泛使用的全功能虚拟机管理程序。该实现的可信计算基础只有几千行代码,比KVM少很多数量级。我们表明,HypSec保护的机密性和完整性的虚拟机运行未经修改的客户操作系统,而只会产生适度的性能开销为真实的应用程序的工作负载。
Hypervisors are widely deployed by cloud computing providers to support virtual machines, but their growing complexity poses a security risk as large codebases contain many vulnerabilities. We have created HypSec, a new hypervisor design for retrofitting an existing commodity hypervisor using microkernel principles to reduce its trusted computing base while protecting the confidentiality and integrity of virtual machines. HypSec partitions the hypervisor into an untrusted host that performs most complex hypervisor functionality without access to virtual machine data, and a trusted core that provides access control to virtual machine data and performs basic CPU and memory virtualization. Hardware virtualization support is used to isolate and protect the trusted core and execute it at a higher privilege level so it can mediate virtual machine exceptions and protect VM data in CPU and memory. HypSec takes an end-to-end approach to securing I/O to simplify its design, with applications increasingly using secure network connections in the cloud. We have used HypSec to retrofit KVM, showing how our approach can support a widely-used full-featured hypervisor integrated with a commodity operating system. The implementation has a trusted computing base of only a few thousand lines of code, many orders of magnitude less than KVM. We show that HypSec protects the confidentiality and integrity of virtual machines running unmodified guest operating systems while only incurring modest performance overhead for real application workloads.