DocumentCode
3662500
Title
Blind hypervision to protect virtual machine privacy against hypervisor escape vulnerabilities
Author
P. Dubrulle;R. Sirdey;P. Doré;M. Aichouch;E. Ohayon
Author_Institution
CEA, LIST, Point Courier 172, FR-91191 Gif-sur-Yvette Cedex, France
fYear
2015
fDate
7/1/2015 12:00:00 AM
Firstpage
1394
Lastpage
1399
Abstract
Hypervision is being widely implemented in an effort to control costs and to simplify management through consolidation of servers. It has been recently unraveled that well over a third of virtualization vulnerabilities reside in the hyper-visor, mostly due to hypervisor escape. The exploitation of these vulnerabilities allows an attacker, among other things, to access and/or modify data of other Virtual Machines (VMs) by escaping from its VM and executing malicious code in the hypervisor. This paper introduces the general idea of blind hypervision, a hardware/software co-design to prevent such attackers to access private elements of other VMs. Blind hypervision limits the rights of the hypervisor regarding memory access, so that a malicious agent executing with hypervisor rights cannot access the data of the VMs.
Keywords
"Virtual machine monitors","Hardware","Memory management","Loading","Software","Registers"
Publisher
ieee
Conference_Titel
Industrial Informatics (INDIN), 2015 IEEE 13th International Conference on
ISSN
1935-4576
Electronic_ISBN
2378-363X
Type
conf
DOI
10.1109/INDIN.2015.7281938
Filename
7281938
Link To Document