TUM Logo

Virtual Machine Introspection with Xen on ARM

In the recent years, virtual machine introspection has become a valuable technique for developing security applications for virtualized environments. With the increasing popularity of the ARM architecture and the recent addition of hardware virtualization extensions there is a growing need for porting existing tools to this new platform. Porting these applications requires proper hypervisor support, which we have been exploring and developing for the upcoming Xen 4.6 release. In this paper we explore using ARM's two-stage paging mechanisms with Xen to enable stealthy, efficient tracing of guest operating systems for security purposes.

Virtual Machine Introspection with Xen on ARM

2nd Workshop on Security in highly connected IT systems (SHCIS)

Authors: Tamas Lengyel, Thomas Kittel, and Claudia Eckert
Year/month: 2015/9
Booktitle: 2nd Workshop on Security in highly connected IT systems (SHCIS)
Fulltext: lengyelshcis2015.pdf

Abstract

In the recent years, virtual machine introspection has become a valuable technique for developing security applications for virtualized environments. With the increasing popularity of the ARM architecture and the recent addition of hardware virtualization extensions there is a growing need for porting existing tools to this new platform. Porting these applications requires proper hypervisor support, which we have been exploring and developing for the upcoming Xen 4.6 release. In this paper we explore using ARM's two-stage paging mechanisms with Xen to enable stealthy, efficient tracing of guest operating systems for security purposes.

Bibtex:

@inproceedings { lengyel2015,
author = { Tamas Lengyel and Thomas Kittel and Claudia Eckert},
title = { Virtual Machine Introspection with Xen on ARM },
year = { 2015 },
month = { September },
booktitle = { 2nd Workshop on Security in highly connected IT systems (SHCIS) },
url = {https://www.sec.in.tum.de/i20/publications/virtual-machine-introspection-with-xen-on-arm/@@download/file/lengyelshcis2015.pdf}
}