RapidVMI: Fast and multi-core aware active virtual machine introspection


연구 분야: Safety



학회: ARES '21: Proceedings of the 16th International Conference on Availability, Reliability and Security


초록

Virtual machine introspection (VMI) is a technique for the external monitoring of virtual machines. Through previous work, it became apparent that VMI can contribute to the security of distributed systems and cloud architectures by facilitating stealthy intrusion detection, malware analysis, and digital forensics. The main shortcomings of active VMI-based approaches such as program tracing or process injection in production environments result from the side effects of writing to virtual address spaces and the parallel execution of shared main memory on multiple processor cores. In this paper, we present RapidVMI, a framework for active virtual machine introspection that enables fine-grained, multi-core aware VMI-based memory access on virtual address spaces. It was built to overcome the outlined shortcomings of existing VMI solutions and facilitate the development of introspection applications as if they run in the monitored virtual machine itself. Furthermore, we demonstrate that hypervisor support for this concept improves introspection performance in prevalent virtual machine tracing applications considerably up to 98 times.


Author Profile
Thomas Dangl

University of Passau Germany

Germany
Author Profile
Benjamin Taubmann

University of Passau Germany

Germany
Author Profile
Hans Peter Reiser

University of Passau Germany

Germany

📄 논문 정보

발행 연도 2021년
인용수 11
출판 국가 Germany
사이트 ACM
좋아요 수 0

연관 논문 목록 (626건)