• Cite Icon2
  • https://doi.org/10.1145/3140607.3050767Copy DOI Icon

HA-VMSI

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Once compromising the hypervisor, remote or local adversaries can easily access other customers' sensitive data in the memory and context of guest virtual machines (VMs). VM isolation is an efficient mechanism for protecting the memory of guest VMs from unauthorized access. However, previous VM isolation systems either modify hardware architecture or introduce a software module without being protected, and most of them focus on the x86 architecture. This paper proposes HA-VMSI, a lightweight hardware-assisted VM isolation approach for ARM, to provide runtime protection of guest VMs, even with a compromised hypervisor. In the ARM TrustZone secure world, a thin security monitor is introduced as HA-VMSI's entire TCB. Hence, the security monitor is much less vulnerable and safe from attacks that can compromise the hypervisor. The key of HA-VMSI is decoupling the functions of memory isolation among VMs from the hypervisor into the security monitor. As a result, the hypervisor can only update the Stage-2 page tables of VMs via the security monitor, which inspects and approves each new mapping. It is worth noting that HA-VMSI is more secure and effective than current software approaches, and more flexible and compatible than hardware approaches. We have implemented a prototype for KVM hypervisor with multiple Linux as guest OSes on Juno board. The security assessment and performance evaluation show that HA-VMSI is effective, efficient and practical.

Similar Papers
  • Conference Article
  • Citations24

Secure MMU: Architectural support for memory isolation among virtual machines

  • Jun 01, 2011
  • Seongwook Jin +1
  • Research Article
  • Citations58

XHive: Efficient Cooperative Caching for Virtual Machines

  • Jan 01, 2011
  • IEEE Transactions on Computers
  • Hwanju Kim +2
  • Conference Article
  • Citations2

Privacy-preserving Virtual Machine

  • Dec 07, 2015
  • Tianlin Li +3
  • Conference Article
  • Citations18

SPARC

  • Oct 17, 2011
  • Mikhail I Gofman +3
  • Conference Article
  • Citations17

Dynamic Memory Pressure Aware Ballooning

  • Oct 05, 2015
  • Jinchun Kim +3
  • Conference Article
  • Citations3

HyperMI: A Privilege-level VM Protection Approach against Compromised Hypervisor

  • Aug 01, 2019
  • Kunli Lin +3
  • Conference Article
  • Citations3

Quick Eviction of Virtual Machines through Proactive Snapshots

  • Sep 01, 2016
  • Dinuni Fernando +6
  • Book Chapter
  • Citations2

A Container-Oriented Virtual-Machine-Introspection-Based Security Monitor to Secure Containers in Cloud Computing

  • Jan 01, 2021
  • Zhaofeng Yu +5
  • Conference Article
  • Citations22

Utilizing Memory Content Similarity for Improving the Performance of Replicated Virtual Machines

  • Dec 01, 2011
  • B Gerofi +2
  • Conference Article
  • Citations262

CloudNet

  • Mar 09, 2011
  • Timothy Wood +3
  • Book Chapter
  • Citations58

Secure and Robust Monitoring of Virtual Machines through Guest-Assisted Introspection

  • Jan 01, 2012
  • Martim Carbone +3
  • Conference Article
  • Citations16

PVTCP: Towards practical and effective congestion control in virtualized datacenters

  • Oct 01, 2013
  • Luwei Cheng +2
  • Research Article
  • Citations29

Optimizing dynamic survivability and security of replicated data in cloud systems under co-residence attacks

  • Sep 25, 2018
  • Reliability Engineering & System Safety
  • Liang Luo +2
  • Conference Article
  • Citations9

Performance Analysis of Encryption in Securing the Live Migration of Virtual Machines

  • Jun 01, 2015
  • Yaohui Hu +7
  • Conference Article
  • Citations7

Accelerating critical OS services in virtualized systems with flexible micro-sliced cores

  • Apr 23, 2018
  • Jeongseob Ahn +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.