• DocumentCode
    2395922
  • Title

    A Case for Hardware Protection of Guest VMs from Compromised Hypervisors in Cloud Computing

  • Author

    Szefer, Jakub ; Lee, Ruby B.

  • Author_Institution
    Dept. of Electr. Eng., Princeton Univ., Princeton, NJ, USA
  • fYear
    2011
  • fDate
    20-24 June 2011
  • Firstpage
    248
  • Lastpage
    252
  • Abstract
    Cloud computing, enabled by virtualization technologies, is becoming a mainstream computing model. Many companies are starting to utilize the infrastructure-as-a-service (IaaS) cloud computing model, leasing guest virtual machines (VMs) from the infrastructure providers for economic reasons: to reduce their operating costs and to increase the flexibility of their own infrastructures. Yet, many companies may be hesitant to move to cloud computing due to security concerns. An integral part of any virtualization technology is the all-powerful hyper visor. A hyper visor is a system management software layer which can access all resources of the platform. Much research has been done on using hypervisors to monitor guest VMs for malicious code and on hardening hypervisors to make them more secure. There is, however, another threat which has not been addressed by researchers - that of compromised or malicious hypervisors that can extract sensitive or confidential data from guest VMs. Consequently, we propose that a new research direction needs to be undertaken to tackle this threat. We further propose that new hardware mechanisms in the multi core microprocessors are a viable way of providing protections for the guest VMs from the hyper visor, while still allowing the hyper visor to flexibly manage the resources of the physical platform.
  • Keywords
    cloud computing; microprocessor chips; multiprocessing systems; security of data; virtual machines; virtualisation; compromised hypervisors; guest VM; guest virtual machines; hardware protection; infrastructure-as-a-service cloud computing model; mainstream computing model; multicore microprocessors; operating costs reduction; system management software layer; virtualization technologies; Cryptography; Hardware; Microprocessors; Servers; Software; Virtual machine monitors; Hardware security; Hypervisors; Security architectures; virtual machines;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Distributed Computing Systems Workshops (ICDCSW), 2011 31st International Conference on
  • Conference_Location
    Minneapolis, MN
  • ISSN
    1545-0678
  • Print_ISBN
    978-1-4577-0384-3
  • Electronic_ISBN
    1545-0678
  • Type

    conf

  • DOI
    10.1109/ICDCSW.2011.51
  • Filename
    5961523