Monday, March 3, 2008

Overshadow: A Virtualization-Based Approach to Retrofitting Protection in Commodity Operating Systems

Authors: Xiaoxin Chen (VMWare), Tal Garfinkel (VMWare), E. Christopher Lewis (VMWare), Pratap Subrahmanyam (VMWare), Carl A. Waldspurger (VMWare), Dan Boneh (Stanford), Jeffrey Dwoskin (Princeton), Dan R. K. Ports (MIT)

Questions:

Q: Cloaking needs to be atomic? How?
A: Has to be atomic w/ respect to OS. No real fallout for concurrent systems.

Q: Why is MARSHALL mini-benchmark worse than PASSTHRU?
A:

Q: Could you reverse it and use it in the OS to protect against malicious VM?
A: Huh. Maybe.

Q: What's your threat model?
A: Don't worry about I/O (things like SSL protect network).

Q: Why is mmap read performance worse than write?
A: Write has to touch disk anyway, so minimal additional overhead. Read needs an extra page fault.

No comments: