Skip to main navigation Skip to search Skip to main content

Shadowmonitor: An effective in-VM monitoring framework with hardware-enforced isolation

  • Bin Shi
  • , Lei Cui*
  • , Bo Li
  • , Xudong Liu
  • , Zhiyu Hao
  • , Haiying Shen
  • *Corresponding author for this work
  • Beihang University
  • CAS - Institute of Information Engineering
  • University of Virginia

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Virtual machine introspection (VMI) is one compelling technique to enhance system security in clouds. It is able to provide strong isolation between untrusted guests and security tools placed in guests, thereby enabling dependability of the security tools even if the guest has been compromised. Due to this benefit, VMI has been widely used for cloud security such as intrusion detection, security monitoring, and tampering forensics. However, existing VMI solutions suffer significant performance degradation mainly due to the high overhead upon frequent memory address translations and context-switches. This drawback limits its usage in many real-world scenarios, especially when fine-grained monitoring is desired. In this paper, we present ShadowMonitor, an effective VMI framework that enables efficient in-VM monitoring without imposing significant overhead. ShadowMonitor decomposes the whole monitoring system into two compartments and then assigns each compartment with isolated address space. By placing the monitored components in the protected compartment, ShadowMonitor guarantees the safety of both monitoring tools and guests. In addition, ShadowMonitor employs hardware-enforced instructions to design the gates across two compartments, thereby providing efficient switching between compartments. We have implemented ShadowMonitor on QEMU/KVM exploiting several hardware virtualization features. The experimental results show that ShadowMonitor could prevent several types of attacks and achieves 10× speedup over the existing method in terms of both event monitoring and overall application performance.

Original languageEnglish
Title of host publicationResearch in Attacks, Intrusions, and Defenses - 21st International Symposium, RAID 2018, Proceedings
EditorsMichael Bailey, Thorsten Holz, Manolis Stamatogiannakis, Sotiris Ioannidis
PublisherSpringer Verlag
Pages670-690
Number of pages21
ISBN (Print)9783030004699
DOIs
StatePublished - 2018
Event21st International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2018 - Heraklion, Greece
Duration: 10 Sep 201812 Sep 2018

Publication series

NameLecture Notes in Computer Science
Volume11050 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference21st International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2018
Country/TerritoryGreece
CityHeraklion
Period10/09/1812/09/18

Keywords

  • Isolation
  • Monitor
  • Virtual machine introspection

Fingerprint

Dive into the research topics of 'Shadowmonitor: An effective in-VM monitoring framework with hardware-enforced isolation'. Together they form a unique fingerprint.

Cite this