Visible to the public Secure Out-of-Band Remote Management of Virtual Machines with Transparent Passthrough

TitleSecure Out-of-Band Remote Management of Virtual Machines with Transparent Passthrough
Publication TypeConference Paper
Year of Publication2018
AuthorsFutagami, Shota, Unoki, Tomoya, Kourai, Kenichi
Conference NameProceedings of the 34th Annual Computer Security Applications Conference
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-6569-7
Keywordscomposability, cryptography, cyber physical systems, information leakage, Nested virtualization, pubcrawl, Remote management, Resiliency, virtual machine security, virtual machines, Virtualized systems
Abstract

Infrastructure-as-a-Service clouds provide out-of-band remote management for users to access their virtual machines (VMs). Out-of-band remote management is a method for indirectly accessing VMs via their virtual devices. While virtual devices running in the virtualized system are managed by cloud operators, not all cloud operators are always trusted in clouds. To prevent information leakage from virtual devices and tampering with their I/O data, several systems have been proposed by trusting the hypervisor in the virtualized system. However, they have various issues on security and management. This paper proposes VSBypass, which enables secure out-of-band remote management outside the virtualized system using a technique called transparent passthrough. VSBypass runs the entire virtualized system in an outer VM using nested virtualization. Then it intercepts I/O requests of out-of-band remote management and processes those requests in shadow devices, which run outside the virtualized system. We have implemented VSBypass in Xen for the virtual serial console and GUI remote access. We confirmed that information leakage was prevented and that the performance was comparable to that in traditional out-of-band remote management.

URLhttps://dl.acm.org/citation.cfm?doid=3274694.3274749
DOI10.1145/3274694.3274749
Citation KeyfutagamiSecureOutofbandRemote2018