• DocumentCode
    3662500
  • Title

    Blind hypervision to protect virtual machine privacy against hypervisor escape vulnerabilities

  • Author

    P. Dubrulle;R. Sirdey;P. Doré;M. Aichouch;E. Ohayon

  • Author_Institution
    CEA, LIST, Point Courier 172, FR-91191 Gif-sur-Yvette Cedex, France
  • fYear
    2015
  • fDate
    7/1/2015 12:00:00 AM
  • Firstpage
    1394
  • Lastpage
    1399
  • Abstract
    Hypervision is being widely implemented in an effort to control costs and to simplify management through consolidation of servers. It has been recently unraveled that well over a third of virtualization vulnerabilities reside in the hyper-visor, mostly due to hypervisor escape. The exploitation of these vulnerabilities allows an attacker, among other things, to access and/or modify data of other Virtual Machines (VMs) by escaping from its VM and executing malicious code in the hypervisor. This paper introduces the general idea of blind hypervision, a hardware/software co-design to prevent such attackers to access private elements of other VMs. Blind hypervision limits the rights of the hypervisor regarding memory access, so that a malicious agent executing with hypervisor rights cannot access the data of the VMs.
  • Keywords
    "Virtual machine monitors","Hardware","Memory management","Loading","Software","Registers"
  • Publisher
    ieee
  • Conference_Titel
    Industrial Informatics (INDIN), 2015 IEEE 13th International Conference on
  • ISSN
    1935-4576
  • Electronic_ISBN
    2378-363X
  • Type

    conf

  • DOI
    10.1109/INDIN.2015.7281938
  • Filename
    7281938