SECvma: Virtualization-based Linux Kernel Protection for Arm
Part Of
Proceedings - Annual Computer Security Applications Conference, ACSAC
Start Page
579
End Page
592
ISBN
[9798331520885]
Date Issued
2024-12-09
Author(s)
DOI
10.1109/ACSAC63791.2024.00056
Abstract
A rootkit or an attacker that exploited a single vulnerability in a monolithic OS kernel like Linux could obtain full authority over the system. We introduce SECvma, a new system with Linux kernel protection for Arm-based platforms. SECvma employs a virtualization-based approach to transparently protect the kernel’s code integrity in its lifetime. SECvma proposes a new design that extends current Linux KVM-based confidential virtual machine (CVM) frameworks to provide standalone Linux kernel protection with modest effort while preserving the safety of CVMs. SECvma leverages Arm’s hardware virtualization extensions and addresses their limitations in supporting kernel protection. SECvma incorporates novel optimizations to reduce the overhead from the virtualization-based approach. SECvma significantly enhances Linux’s security while retaining its performance efficiency and standard features, including dynamic kernel module loading and kernel page table isolation (KPTI).
Event(s)
40th Annual Computer Security Applications Conference, ACSAC 2024
SDGs
Publisher
IEEE
Type
conference paper
