Security Implications of Memory Deduplication in a Virtualized Environment

被引:0
|
作者
Xiao, Jidong [1 ]
Xu, Zhang [1 ]
Huang, Hai [2 ]
Wang, Haining [1 ]
机构
[1] Coll William & Mary, Williamsburg, VA 23186 USA
[2] IBM Corp, TJ Watson Res Ctr, Hawthorne, NY USA
基金
美国国家科学基金会;
关键词
ROOTKITS;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Memory deduplication has been widely used in various commodity hypervisors. By merging identical memory contents, it allows more virtual machines to run concurrently on top of a hypervisor. However, while this technique improves memory efficiency, it has a large impact on system security. In particular, memory deduplication is usually implemented using a variant of copy-on-write techniques, for which, writing to a shared page would incur a longer access time than those non-shared. In this paper, we investigate the security implication of memory deduplication from the perspectives of both attackers and defenders. On one hand, using the artifact above, we demonstrate two new attacks to create a covert channel and detect virtualization, respectively. On the other hand, we also show that memory deduplication can be leveraged to safeguard Linux kernel integrity.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] Memory Deduplication as a Protective Factor in Virtualized Systems
    Albalawi, Abdullah
    Vassilakis, Vassilios
    Calinescu, Radu
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY WORKSHOPS, ACNS 2021, 2021, 12809 : 301 - 317
  • [2] A Memory Deduplication Approach Based on Group in Virtualized Environments
    Deng, Yan
    Hu, Chunming
    Wo, Tianyu
    Li, Bo
    Cui, Lei
    2013 IEEE SEVENTH INTERNATIONAL SYMPOSIUM ON SERVICE-ORIENTED SYSTEM ENGINEERING (SOSE 2013), 2013, : 367 - 372
  • [3] Group-Based Memory Deduplication for Virtualized Clouds
    Kim, Sangwook
    Kim, Hwanju
    Lee, Joonwon
    EURO-PAR 2011: PARALLEL PROCESSING WORKSHOPS, PT II, 2012, 7156 : 387 - 397
  • [4] Breaking KASLR Using Memory Deduplication in Virtualized Environments
    Kim, Taehun
    Kim, Taehyun
    Shin, Youngjoo
    ELECTRONICS, 2021, 10 (17)
  • [5] Security Incident Tracking in Virtualized Linux Environment
    Tu, Manghui
    Xue, Shiming
    2014 ASEE ANNUAL CONFERENCE, 2014,
  • [6] Group-based Memory Deduplication against Covert Channel Attacks in Virtualized Environments
    Ning, Fangxiao
    Zhu, Min
    You, Ruibang
    Shi, Gang
    Meng, Dan
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 194 - 200
  • [7] Towards an Automated Security Awareness System in a Virtualized Environment
    Labuschagne, William Aubrey
    Eloff, Mariki
    PROCEEDINGS OF THE 11TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2012, : 163 - 171
  • [8] The page cache deduplication mechanism in virtualized systems
    Lee, Seho
    Kim, Inhyeok
    Lee, Dongwoo
    Eom, Young Ik
    International Journal of Control and Automation, 2013, 6 (01): : 151 - 160
  • [9] EagleEye: Towards Mandatory Security Monitoring in Virtualized Datacenter Environment
    Wu, Yu-Sung
    Sun, Pei-Keng
    Huang, Chun-Chi
    Lu, Sung-Jer
    Lai, Syu-Fang
    Chen, Yi-Yung
    2013 43RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2013,
  • [10] Modified security and cryptography-based data deduplication in cloud environment
    Kumar, Doddi Suresh
    Srinivasu, Nulaka
    INTERNATIONAL JOURNAL OF MODELING SIMULATION AND SCIENTIFIC COMPUTING, 2025,