SecPod: a framework for virtualization-based security systems

Xiaoguang Wang, Yue Chen, Zhi Wang, Yong Qi, Yajin Zhou · 2015

The OS kernel is critical to the security of a computer system. Many systems have been proposed to improve its security. A fundamental weakness of those systems is that page tables, the data structures that control the memory protection, are not isolated from the vulnera-ble kernel, and thus subject to tampering. To address that, researchers have relied on virtualization for reliable kernel memory protection. Unfortunately, such memory protection requires to monitor every update to the guest’s page tables. This fundamentally conflicts with the re-cent advances in the hardware virtualization support. In this paper, we propose SecPod, an extensible framework for virtualization-based security systems that can provide both strong isolation and the compatibility with mod-ern hardware. SecPod has two key techniques: paging delegation delegates and audits the kernel’s paging opera-tions to a secure space; execution trapping intercepts the (compromised) kernel’s attempts to subvert SecPod by misusing privileged instructions. We have implemented a prototype of SecPod based on KVM. Our experiments show that SecPod is both effective and efficient. 1

Read the paper · More papers on PaperTik