SMM-Based Hypervisor Integrity Measurement

W. A. R. Souza, A. Tomlinson
{"title":"SMM-Based Hypervisor Integrity Measurement","authors":"W. A. R. Souza, A. Tomlinson","doi":"10.1109/CSCloud.2015.57","DOIUrl":null,"url":null,"abstract":"Hypervisors play an important role in the virtualised environment and consequently are a prime target for attacks. Different kinds of attacks have been reported and a great deal of research has been done to address vulnerabilities in hypervisors. Recently, after successful defeat of integrity measurement tools, a new class of measurement tools have been developed capitalising on the SMM to measure the integrity of hypervisors and other system components. Although those new tools are successful in their tasks, they do not take full advantage of the main benefits of SMM: isolation and stealth. We argue that this is due to the architecture those tools employ. Thus, in this paper, we establish a set of requirements and propose a generic architecture to build and deploy an SMM-based hypervisor integrity measurement tool. We believe that such an architecture might be applied to any SMM-based tool.","PeriodicalId":278090,"journal":{"name":"2015 IEEE 2nd International Conference on Cyber Security and Cloud Computing","volume":"24 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-11-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 IEEE 2nd International Conference on Cyber Security and Cloud Computing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSCloud.2015.57","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Hypervisors play an important role in the virtualised environment and consequently are a prime target for attacks. Different kinds of attacks have been reported and a great deal of research has been done to address vulnerabilities in hypervisors. Recently, after successful defeat of integrity measurement tools, a new class of measurement tools have been developed capitalising on the SMM to measure the integrity of hypervisors and other system components. Although those new tools are successful in their tasks, they do not take full advantage of the main benefits of SMM: isolation and stealth. We argue that this is due to the architecture those tools employ. Thus, in this paper, we establish a set of requirements and propose a generic architecture to build and deploy an SMM-based hypervisor integrity measurement tool. We believe that such an architecture might be applied to any SMM-based tool.
基于smm的Hypervisor完整性度量
管理程序在虚拟化环境中扮演着重要的角色,因此也是攻击的主要目标。已经报告了不同类型的攻击,并且已经进行了大量研究以解决管理程序中的漏洞。最近,在完整性测量工具被成功击败之后,一类新的测量工具被开发出来,利用SMM来测量管理程序和其他系统组件的完整性。尽管这些新工具在它们的任务中取得了成功,但它们并没有充分利用SMM的主要优点:隔离和隐身。我们认为这是由于这些工具所采用的体系结构。因此,在本文中,我们建立了一组需求,并提出了构建和部署基于smm的管理程序完整性度量工具的通用体系结构。我们相信这样的架构可以应用于任何基于smm的工具。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信