RUS  ENG
Full version
JOURNALS // Proceedings of the Institute for System Programming of the RAS // Archive

Proceedings of ISP RAS, 2015 Volume 27, Issue 3, Pages 267–278 (Mi tisp150)

Remote service of system calls in microkernel hypervisor

Kurbanmagomed Mallachieva, Nikolay Pakulinb

a Lomonosov Moscow State University, Faculty of Computational Mathematics and Cybernetics
b Institute for System Programming of the Russian Academy of Sciences

Abstract: This paper presents further development of Sevigator hypervisor-based security system. Original design of Sevigator confines users’ applications in a separate virtual machine that has no network interfaces. For trusted applications Sevigator intercepts network-related system calls and routes them to the dedicated virtual machine that services those calls. This design allows Sevigator protect networking from malicious applications including high-level intruders residing in the kernel. Modern microkernel-based hypervisors opened the door to redesign of Sevigator. Those hypervisors are small operating systems by nature, where management of virtual machines as well as most of hardware operations are isolated in processes with low priority level. Compromising such a process does not result in compromising the whole hypervisor.
In this paper we present an experimental design of Sevigator based on NOVA hypervisor where system calls of trusted applications are serviced by a dedicated process in the hypervisor rather than a separate VM. The experiment shows about 25% performance gain due to reduced number of context switches.

Keywords: virtualization, hypervisor, security, microkernel.

Language: English

DOI: 10.15514/ISPRAS-2015-27(3)-18



Bibliographic databases:


© Steklov Math. Inst. of RAS, 2024