AI 中文总结
RealmEye是首个面向Arm CCA Realm虚拟机的虚拟机内省系统,将内省逻辑置于RMM中,无需修改Realm即可检测rootkit,兼容现有工具,在Arm FVP上可有效检测Diamorphine rootkit的恶意行为。
AI 中文摘要
机密虚拟机(Confidential VMs,CVMs)已成为金融服务、隐私保护AI推理等敏感云工作负载的主导基础。保护这些CVM免受恶意云攻击的硬件隔离机制,也导致其所有者无法知晓内部运行的内容:通过网络或供应链攻击植入的内核 rootkit(rootkit 工具)可隐藏进程、篡改内核数据,并在保护CVM的隔离机制掩护下 exfiltrate(泄露)模型权重。因此租户需要从外部检查运行中的CVM,但传统虚拟机内省(Virtual Machine Introspection,VMI)依赖可信的 Hypervisor(虚拟机监控器),而CVM将其排除在TCB(可信计算基)之外。最先进的CVM-VMI系统00SEVen通过在VM特权层(VMPL0)部署VM内代理,在AMD SEV-SNP上恢复了内省功能,但该机制在Arm CCA上不存在,导致Realm VMs(Realm虚拟机)缺乏任何内省解决方案。本文提出RealmEye,是首个面向Arm CCA Realm VMs的VMI系统。RealmEye将全部内省逻辑置于R-EL2层级的Realm Management Monitor(RMM,Realm管理监控器)中,实现监控器与被监控VM之间的硬件强制隔离:无需在Realm内部署任何代理,且Realm保持未修改状态。RealmEye可读取Realm内存和寄存器、暂停VM以获取一致快照、捕获页级访问,且不依赖任何VM内接口。其周期性自驱动触发模式将扫描计时逻辑置于RMM内部,防止Hypervisor与Realm内rootkit合谋。结果通过硬件认证通道返回给远程所有者,且CCA驱动后端可让LibVMI、DRAKVUF等现有工具无需修改即可与RealmEye交互。在Arm FVP上的实验显示,RealmEye可检测Diamorphine rootkit的进程隐藏和系统调用表挂钩,其RMM内部开销可通过原语调用数量线性预测。
英文摘要
Confidential VMs (CVMs) have become the dominant substrate for sensitive cloud workloads, from financial services to privacy-preserving AI inference. The hardware isolation that protects these CVMs from a malicious cloud also blinds their owners to what runs inside them: kernel rootkits planted via network or supply-chain attacks can hide processes, tamper with kernel data, and exfiltrate model weights under the cover of the same isolation that defends the VM. Tenants therefore need to inspect a running CVM from outside, yet classical VM introspection (VMI) presupposes a trusted Hypervisor, which CVMs exclude from the TCB. The state-of-the-art CVM-VMI system, 00SEVen, restores introspection on AMD SEV-SNP via an in-VM agent at a privileged tier (VMPL0), a mechanism that does not exist on Arm CCA, leaving Realm VMs without any introspection solution. We present RealmEye, the first VMI system for Arm CCA Realm VMs. RealmEye places the entire introspection logic inside the Realm Management Monitor (RMM) at R-EL2, achieving hardware-enforced separation between the monitor and the monitored VM: no agent runs inside the Realm, and the Realm remains unmodified. RealmEye reads Realm memory and registers, suspends the VM for consistent snapshots, and traps page-level accesses, without relying on any in-VM interface. A periodic, self-driven trigger mode keeps scan timing internal to the RMM, preventing the Hypervisor from colluding with in-Realm rootkits. Results are returned to the remote owner over a hardware-attested channel, and a CCA driver backend lets existing tools such as LibVMI and DRAKVUF interoperate with RealmEye unchanged. On the Arm FVP, RealmEye detects process hiding and syscall-table hooking by Diamorphine, and its in-RMM cost is linearly predictable from primitive invocation counts.
Comments14 pages. Preprint