Hypervisor-based protection of sensitive files in a compromised system
Junqing Wang, Miao Yu, Bingyu Li, Zhengwei Qi, Haibing Guan · 2012
One of the most fundamental issues in computer security is protecting sensitive files from unauthorized access. Traditional file protection tools run inside the target operating system, which hosts sensitive files. This makes previous approaches vulnerable in face of a compromised OS. To address this limitation, recent approaches seek for a good isolation by putting file system into a dedicated virtual machine or by using a network file system. However, they suffer a sharp increase in trusted computing base size which degrades their reliability.