• DocumentCode
    265681
  • Title

    Analysis of Monolithic and Microkernel Architectures: Towards Secure Hypervisor Design

  • Author

    Shropshire, Jordan

  • Author_Institution
    Dept. of Inf. Technol., Georgia Southern Univ., Atlanta, GA, USA
  • fYear
    2014
  • fDate
    6-9 Jan. 2014
  • Firstpage
    5008
  • Lastpage
    5017
  • Abstract
    This research focuses on hyper visor security from holistic perspective. It centers on hyper visor architecture - the organization of the various subsystems which collectively compromise a virtualization platform. It holds that the path to a secure hyper visor begins with a big-picture focus on architecture. Unfortunately, little research has been conducted with this perspective. This study investigates the impact of monolithic and micro kernel hyper visor architectures on the size and scope of the attack surface. Six architectural features are compared: management API, monitoring interface, hyper calls, interrupts, networking, and I/O. These subsystems are core hyper visor components which could be used as attack vectors. Specific examples and three leading hyper visor platforms are referenced (ESXi for monolithic architecture; Xen and Hyper-V for micro architecture). The results describe the relative strengths and vulnerabilities of both types of architectures. It is concluded that neither design is more secure, since both incorporate security tradeoffs in core processes.
  • Keywords
    application program interfaces; security of data; virtualisation; ESXi; Hyper-V; Xen; attack surface; hyper calls; hyper visor security; management API; micro architecture; micro kernel hyper visor architectures; microkernel architectures; monitoring interface; monolithic architectures; monolithic hyper visor architectures; networking; secure hyper visor design; security tradeoffs; virtualization platform; Computer architecture; Hardware; Kernel; Monitoring; Security; Virtual machine monitors; Virtual machining; cloud computing; hypervisor security; microkernel architecture; monolithic architecture;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    System Sciences (HICSS), 2014 47th Hawaii International Conference on
  • Conference_Location
    Waikoloa, HI
  • Type

    conf

  • DOI
    10.1109/HICSS.2014.615
  • Filename
    6759218