Skip to main navigation Skip to search Skip to main content

HyperForce: Hypervisor-enforced execution of security-critical code

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

The sustained popularity of the cloud and cloud-related services accelerate the evolution of virtualization-enabling technologies. Modern off-the-shelf computers are already equipped with specialized hardware that enables a hypervisor to manage the simultaneous execution of multiple operating systems. Researchers have proposed security mechanisms that operate within such a hypervisor to protect the virtualized operating systems from attacks. These mechanisms improve in security over previous techniques since the defense system is no longer part of an operating system's attack surface. However, due to constant transitions between the hypervisor and the operating systems, these countermeasures typically incur a significant performance overhead. In this paper we present HyperForce, a framework which allows the deployment of security-critical code in a way that significantly outperforms previous in-hypervisor systems while maintaining similar guarantees with respect to security and integrity. HyperForce is a hybrid system which combines the performance of an in-guest security mechanism with the security of in-hypervisor one. We evaluate our framework by using it to re-implement an invariance-based rootkit detection system and show the performance benefits of a HyperForce-utilizing countermeasure.

Original languageEnglish
Title of host publicationInformation Security and Privacy Research - 27th IFIP TC 11 Information Security and Privacy Conference, SEC 2012, Proceedings
Pages126-137
Number of pages12
DOIs
StatePublished - 2012
Event27th IFIP TC 11 Information Security and Privacy Conference, SEC 2012 - Heraklion, Crete, Greece
Duration: Jun 4 2012Jun 6 2012

Publication series

NameIFIP Advances in Information and Communication Technology
Volume376 AICT

Conference

Conference27th IFIP TC 11 Information Security and Privacy Conference, SEC 2012
Country/TerritoryGreece
CityHeraklion, Crete
Period06/4/1206/6/12

Keywords

  • countermeasure
  • hypervisor
  • virtual devices
  • virtualization

Fingerprint

Dive into the research topics of 'HyperForce: Hypervisor-enforced execution of security-critical code'. Together they form a unique fingerprint.

Cite this