HAL will be down for maintenance from Friday, June 10 at 4pm through Monday, June 13 at 9am. More information
Skip to Main content Skip to Navigation
Conference papers

Towards Hypervisor Support for Enhancing the Performance of Virtual Machine Introspection

Abstract : Virtual machine introspection (VMI) is the process of external monitoring of virtual machines. Previous work has demonstrated that VMI can contribute to the security of cloud environments and distributed systems, as it enables, for example, stealthy intrusion detection. One of the biggest challenges for applying VMI in production environments is the performance overhead that certain tracing operations impose on the monitored virtual machine. In this paper, we show how this performance overhead can be significantly minimized by incorporating minor extensions for VMI operations into the hypervisor. In a proof-of-concept implementation, we demonstrate that the pre-processing of VMI events in the Xen hypervisor reduces the monitoring overhead for the use case of VMI-based process-bound monitoring by a factor of 18.
Complete list of metadata

https://hal.inria.fr/hal-03223259
Contributor : Hal Ifip Connect in order to contact the contributor
Submitted on : Monday, May 10, 2021 - 5:41:33 PM
Last modification on : Monday, May 10, 2021 - 5:45:32 PM
Long-term archiving on: : Wednesday, August 11, 2021 - 8:08:23 PM

File

 Restricted access
To satisfy the distribution rights of the publisher, the document is embargoed until : 2023-01-01

Please log in to resquest access to the document

Licence


Distributed under a Creative Commons Attribution 4.0 International License

Identifiers

Citation

Benjamin Taubmann, Hans Reiser. Towards Hypervisor Support for Enhancing the Performance of Virtual Machine Introspection. 20th IFIP International Conference on Distributed Applications and Interoperable Systems (DAIS), Jun 2020, Valletta, Malta. pp.41-54, ⟨10.1007/978-3-030-50323-9_3⟩. ⟨hal-03223259⟩

Share

Metrics

Record views

60