2007
DOI: 10.1145/1323293.1294294
|View full text |Cite
|
Sign up to set email alerts
|

SecVisor

Abstract: We propose SecVisor, a tiny hypervisor that ensures code integrity for commodity OS kernels. In particular, SecVisor ensures that only user-approved code can execute in kernel mode over the entire system lifetime. This protects the kernel against code injection attacks, such as kernel rootkits. SecVisor can achieve this propertyeven against an attacker who controls everything but the CPU, the memory controller, and system memory chips. Further, SecVisor can even defend against attackers with knowledge of zero-… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

1
8
0

Year Published

2011
2011
2020
2020

Publication Types

Select...
4
3

Relationship

0
7

Authors

Journals

citations
Cited by 82 publications
(9 citation statements)
references
References 9 publications
1
8
0
Order By: Relevance
“…This conforms to expectations in that the more thorough the security [45] CF 5579 SVA [44] M & CF No Data SecVisor [41] M 4092 SBCFI [46] CF No Data kGuard [22] CF 1000 PaX [49], [50] M & CF No Data Return-less Kernel [48] CF 2100…”
Section: (Ijacsa) International Journal Of Advanced Computer Science Andsupporting
confidence: 76%
See 1 more Smart Citation
“…This conforms to expectations in that the more thorough the security [45] CF 5579 SVA [44] M & CF No Data SecVisor [41] M 4092 SBCFI [46] CF No Data kGuard [22] CF 1000 PaX [49], [50] M & CF No Data Return-less Kernel [48] CF 2100…”
Section: (Ijacsa) International Journal Of Advanced Computer Science Andsupporting
confidence: 76%
“…SecVisor [41] is an alternative virtualization technology leveraging hardware facilities to virtualize physical memory associated with modern processors. By utilizing this additional layer of translation from "guest physical" to "real physical" memory addresses, additional hardware memory protections can be enforced.…”
Section: B Secvisormentioning
confidence: 99%
“…Our initial code base was extracted from CMU's SecVisor's code [25]. However, we made various simplifications to eliminate functionality orthogonal to our concerns and to simplify our initial proof target.…”
Section: High Level Strategymentioning
confidence: 99%
“…Several research efforts have demonstrated that it is possible to construct small, robust and useful hypervisors. The SecVisor project [25] implemented two hypervisors (1739 and 1112 lines of code, respectively) supporting Linux kernel version 2.6.20. Their systems provide strong integrity guarantees.…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation