Write a Blog >>
VEE 2017
Sat 8 - Sun 9 April 2017 Xi'an, China
Sun 9 Apr 2017 11:45 - 12:15 at Zhu Que Room - Performance Chair(s): Paolo Bonzini

Once compromising the hypervisor, remote or local adversaries can easily access other customers’ sensitive data in the memory and context of guest virtual machines (VMs). VM isolation is an efficient mechanism for protecting the memory of guest VMs from unauthorized access. However, previous VM isolation systems either modify hardware architecture or introduce a software module without being protected, and most of them focus on the x86 architecture.

This paper proposes HA-VMSI, a lightweight hardware-assisted VM isolation approach for ARM, to provide runtime protection of guest VMs, even with a compromised hypervisor. In the ARM TrustZone secure world, a thin security monitor is introduced as HA-VMSI’s entire TCB. Hence, the security monitor is much less vulnerable and safe from attacks that can compromise the hypervisor. The key of HA-VMSI is decoupling the functions of memory isolation among VMs from the hypervisor into the security monitor. As a result, the hypervisor can only update the Stage-2 page tables of VMs via the security monitor, which inspects and approves each new mapping. It is worth noting that HA-VMSI is more secure and effective than current software approaches, and more flexible and compatible than hardware approaches. We have implemented a prototype for KVM hypervisor with multiple Linux as guest OSes on Juno board. The security assessment and performance evaluation show that HA-VMSI is effective, efficient and practical.

Sun 9 Apr

Displayed time zone: Azores change

10:45 - 12:15
PerformanceSession 6 at Zhu Que Room
Chair(s): Paolo Bonzini Red Hat, Inc.
10:45
30m
Talk
Content Look-Aside Buffer for Redundancy-Free Virtual Disk I/O and Caching
Session 6
Chun Yang Peking University, China, Xianhua Liu Peking University, China, Xu Cheng Peking University, China
11:15
30m
Talk
HyperMAMBO-X64: Using Virtualization to Support High-Performance Transparent Binary Translation
Session 6
Amanieu d'Antras University of Manchester, Cosmin Gorgovan University of Manchester, Jim Garside University of Manchester, John Goodacre University of Manchester, Mikel Luján
File Attached
11:45
30m
Talk
HA-VMSI: A Lightweight Virtual Machine Isolation Approach with Commodity Hardware for ARM
Session 6
Min Zhu Institute of Information Engineering, Chinese Academy of Sciences, Bibo Tu Institute of Information Engineering, Chinese Academy of Sciences, Wei Wei Institute of Information Engineering, Chinese Academy of Sciences, Dan Meng Institute of Information Engineering, Chinese Academy of Sciences