SECvma: Virtualization-based Linux Kernel Protection for Arm
Teh Beng Yen, J. Li, Shih-Wei Li · 2024
A rootkit or an attacker that exploited a single vulnerability in a monolithic OS kernel like Linux could obtain full authority over the system. We introduce SECvma, a new system with Linux kernel protection for Arm-based platforms. SECvma employs a virtualization-based approach to transparently protect the kernel’s code integrity in its lifetime. SECvma proposes a new design that extends current Linux KVM-based confidential virtual machine (CVM) frameworks to provide standalone Linux kernel protection with modest effort while preserving the safety of CVMs. SECvma leverages Arm’s hardware virtualization extensions and addresses their limitations in supporting kernel protection. SECvma incorporates novel optimizations to reduce the overhead from the virtualization-based approach. SECvma significantly enhances Linux’s security while retaining its performance efficiency and standard features, including dynamic kernel module loading and kernel page table isolation (KPTI).