Enforcing memory protection with hardware virtualization

Jon R. Everett · NORA - Norwegian Open Research Archives · 2010

ENGELSK: A monolithic operating system (OS) - such as Windows or Linux - distinguish between executing in restricted user mode or privileged kernel mode. Third party device drivers and modules are executing in kernel mode alongside the code of the OS, thus has direct access to memory, hardware devices and execution state. Limitations in memory protection makes it possible to modify any memory, including read-only. This is exploited by kernel malware to manipulate the code and workflow of the OS. Security software such as integrity checkers, anti-virus and host-firewalls attempt to mitigate this threat, but are also prone to subversion. It is arguably impossible to implement effective security on a privilege level equal to the malicious code, and implemented in the very environment to be protected. Hardware virtualization indroduces a new privilege level superior to the OS. This technology is designed to utilize ample computational resources by collocating several operating systems on one physical machine. A hypervisor manage and monitor virtual machines by intercepting privileged instructions and events. The idea behind this work is to leverage the hypervisor to protect kernel memory in a way the OS itself is not able to. This thesis investigates whether the hypervisor provides a suitable environment for preventing unwanted memory modifications. Memory management, kernel attack surface and hardwareassisted virtualization are addressed to enumerate protection limitations and opportunities. Based on this, a set of techniques to prevent modification of memory in need of protection is presented. The hypervisor is used to intercept and deny attempts to write to memory defined as protected. A prototype of the proposed protection is demonstrated in a simulated attack scenario. The malicious modification attempts are successfully prevented, thus protecting the kernel from a known design vulnerability.

Read the paper · More papers on PaperTik