250 Hutchison Rd, Rochester, NY 14620

View map

Ethan Johnson, "Securing and Accelerating Hypervisors with Virtual Instruction Set Computing"

Advisor: Prof. John Criswell (Computer Science)  

Committee: Prof. Chen Ding (Computer Science), Prof. Michael L. Scott (Computer Science), Prof. Emmett Witcher (UT Austin)

Chair: William R. Donaldson (Laboratory for Laser Energetics)

Modern cloud computing promises a compelling bargain: by virtualizing and containerizing our digital application workloads, we can safely and efficiently enable mutually distrustworthy tenants to share the same physical hardware by extending the same time-sharing techniques that have long been the foundation of multitasking operating systems. The widespread deployment and adoption of virtualization has delivered massive gains in economies of scale, modularity, and resiliency, enabling even the smallest tenants to fluidly access tailored yet staggeringly powerful computing resources while benefiting from levels of redundancy and operational assurance that were once the exclusive province of large enterprises with full-time IT divisions. Today, even hobbyists and undergraduate students routinely deploy network applications to public clouds like Amazon Web Services (AWS) and Microsoft Azure, enjoying their own private slice of enterprise-level datacenter infrastructure for a few dollars a month.

This entire concept is premised on the idea that virtualized, shared systems can provide strong security boundaries between tenants. In modern clouds, the lion's share of that security responsibility is placed upon the hypervisor, the software layer responsible for providing each tenant with a virtualized view of a complete computer system, called a "virtual machine" (VM). The hypervisor mediates between those VMs and the physical hardware on which they run, ensuring the critical security dimensions of confidentiality, integrity, and availability are upheld between VMs even as they "live in the same brain", computationally speaking.

But hypervisors, like operating system kernels before them, are ultimately just software---complex, intricate works of logic, vulnerable to all manner of mistakes and abstraction violations that can undermine the security guarantees they are supposed to uphold. Critical hypervisor vulnerabilities are discovered and exploited every year, compromising the valuable data and responsibilities with which users entrust these systems and shaking confidence in the feasibility of deploying sensitive workloads in public clouds. Many of these vulnerabilities occur at the lowest levels of software abstraction, calling for solutions that understand and address the semantic gaps that arise from their nuanced interactions with the computer's hardware and other software.

Prior work has shown that virtual instruction set computing (VISC) techniques are a highly effective way to implement strong security hardening in low-level, privileged-mode operating system software with competitive performance tradeoffs. This dissertation posits, and demonstrates, the thesis that such techniques can be applied effectively to virtual machine hypervisors, and in fact tend to yield much more favorable security/performance tradeoffs in this context due to the high trust and small runtime fraction required of hypervisors compared to operating system kernels. Furthermore, these techniques can be used not only to add hardening to existing threat models, but also to supplant existing hardware-based isolation relied upon by hypervisors—and in some contexts, this has the potential to dramatically improve performance compared to the conventional non-VISC approaches in common use.

Event Details

See Who Is Interested

0 people are interested in this event


Join Zoom Meeting

Zoom Room ID: 956 2077 1777 

Password: 360679

User Activity

No recent activity

Search

Before you search, check out frequently accessed links below.

Quick access

For current students, faculty, and staff

URochester Dandelion