Architectural requirements for constructing hardware supported sandboxes

Marcel Eckert, Jan Haase, Dominik Meyer, Bernd Klauer · 2016

Malicious stealth software can detect being executed in a virtual machine and thus behave differently. If the system virtualization however is moved to the hardware level, the malware is fooled and can be identified and monitored. This paper gives an overview of requirements for a hardware supported virtualization facility implemented on an FPGA. These requirements are examined along the lines of the basic parts of a typical computer architecture: the processor, memory, and devices. A proof-of-concept demonstrator was implemented on several Xilinx Evaluation boards.

Read the paper · More papers on PaperTik