Bypassing Full Disk Encryption with Virtual Machine Introspection

被引:0
|
作者
Hebbal, Yacine [1 ]
机构
[1] Orange Labs, Secur Dept, Caen, France
关键词
Infrastructure-as-a-Service; Cloud Security; Full Disk Encryption; Virtual Machine Introspection; Binary Code Instrumentation;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Full Disk Encryption (FDE) is a common practice today to reduce the risk of unauthorized access to personal data in public cloud environments. Some research works demonstrated that a malicious hypervisor employing Virtual Machine Introspection (VMI) can bypass FDE and perform unwanted file operations. However, these works provide restricted OS support, enable access only to user level files and may not support complex uses cases. In this paper, we present a new approach for bypassing FDE using VM kernel functions instrumentation. Our approach is portable over different FDE solutions, supports Linux and Windows OSes and provides fast access to user and system files on the VM disk. In addition it enables with no modification existing applications on the host OS to transparently bypass FDE and operate on the VM disk.
引用
收藏
页数:8
相关论文
共 50 条
  • [31] Malware detection for container runtime based on virtual machine introspection
    Xinfeng He
    Riyang Li
    The Journal of Supercomputing, 2024, 80 (6) : 7245 - 7268
  • [32] Memory Forensics Using Virtual Machine Introspection for Malware Analysis
    Tien, Chin-Wei
    Liao, Jian-Wei
    Chang, Shun-Chieh
    Kuo, Sy-Yen
    2017 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING, 2017, : 518 - 519
  • [33] TLSkex: Harnessing virtual machine introspection for decrypting TLS communication
    Taubmann, Benjamin
    Fraedrich, Christoph
    Dusold, Dominik
    Reiser, Hans P.
    DIGITAL INVESTIGATION, 2016, 16 : S114 - S123
  • [34] CloudVMI: A Cloud-Oriented Writable Virtual Machine Introspection
    Qiang, Weizhong
    Xu, Gongping
    Dai, Weiqi
    Zou, Deqing
    Jin, Hai
    IEEE ACCESS, 2017, 5 : 21962 - 21976
  • [35] Concurrent and Consistent Virtual Machine Introspection with Hardware Transactional Memory
    Liu, Yutao
    Xia, Yubin
    Guan, Haibing
    Zang, Binyu
    Chen, Haibo
    2014 20TH IEEE INTERNATIONAL SYMPOSIUM ON HIGH PERFORMANCE COMPUTER ARCHITECTURE (HPCA-20), 2014, : 416 - 427
  • [36] Networking Introspection and Analysis for Virtual Machine Migration in Federated Clouds
    Andronico, Giuseppe
    Bua, Filippo
    Fargetta, Marco
    Giorgio, Emidio
    Guglielmo, Alessio
    Monforte, Salvatore
    Paone, Maurizio
    Villari, Massimo
    ADVANCES IN SERVICE-ORIENTED AND CLOUD COMPUTING (ESOCC 2015), 2016, 567 : 353 - 362
  • [37] Towards virtual machine introspection based security framework for cloud
    Borisaniya, Bhavesh
    Patel, Dhiren
    SADHANA-ACADEMY PROCEEDINGS IN ENGINEERING SCIENCES, 2019, 44 (02):
  • [38] VMOffset: Semantic Reconstruction Improvement Method in Virtual Machine Introspection
    Chen X.-S.
    Cai M.-J.
    Wang W.
    Wang Q.-X.
    Jin X.
    Ruan Jian Xue Bao/Journal of Software, 2021, 32 (10): : 3293 - 3309
  • [39] Full Disk Encryption: A Comparison on Data Management Attributes
    Hasan, Shiza
    Awais, Muhammad
    Shah, Munam Ali
    2ND INTERNATIONAL CONFERENCE ON INFORMATION SYSTEM AND DATA MINING (ICISDM 2018), 2018, : 39 - 43
  • [40] Towards virtual machine introspection based security framework for cloud
    Bhavesh Borisaniya
    Dhiren Patel
    Sādhanā, 2019, 44