Secure Monitoring of Confidential VMs with Isolated Agents
Tomoharu Nono, Kenichi Kourai · 2025
To prevent insiders from eavesdropping on sensitive information in virtual machines (VMs), recent clouds provide confidential VMs, whose memory is transparently encrypted. Since even confidential VMs cannot protect data from intruders inside them, it is still necessary to use intrusion detection systems (IDS). IDS offloading is used to run host-based IDS outside VMs and prevent IDS from being disabled by intruders. However, offloaded IDS cannot monitor information in the memory of confidential VMs due to memory encryption. This paper proposes SEVmonitor for enabling IDS offloading by running agents inside confidential VMs. Offloaded IDS running in another confidential VM securely obtains memory data from the agent in the target VM. To enhance the security of the agent, SEVmonitor confines a target system in an isolated execution environment created in the target VM and runs the agent outside it. It supports two types of isolated execution environments, a container and an inner VM, to take various tradeoffs. We have implemented SEVmonitor using KVM, Linux, BitVisor, and Xen, and examined monitoring and system performance.