Improving Xen Security through Disaggregation
- π€ Speaker: Derek Murray (University of Cambridge)
- π Date & Time: Tuesday 26 February 2008, 15:30 - 16:00
- π Venue: Lecture Theatre 1, Computer Laboratory, William Gates Builiding
Abstract
Virtual machine monitors (VMMs) have been hailed as the basis for an increasing number of reliable or trusted computing systems. The Xen VMM is a relatively small piece of software—a hypervisor—that runs at a lower level than a conventional operating system in order to provide isolation between virtual machines: its size is offered as an argument for its trustworthiness. However, the management of a Xen-based system requires a privileged, full-blown operating system to be included in the trusted computing base (TCB).
In this talk, I will introduce our work to disaggregate the management virtual machine in a Xen-based system. I will present a study of the Xen architecture and explain why the status quo results in a large TCB . I will challenge the conventional wisdom that smaller TCBs are necessarily better, and argue that the “surface area” of the TCB is as important as its size. I will then describe how we implemented our approach on Xen, by moving the domain builder—the most important privileged component—into a minimal trusted compartment. I will also discuss some of the ongoing work that is based on our disaggregation approach.
Series This talk is part of the Computer Laboratory Systems Research Group Seminar series.
Included in Lists
- All Talks (aka the CURE list)
- bld31
- Cambridge Centre for Data-Driven Discovery (C2D3)
- Cambridge talks
- Chris Davis' list
- CL's SRG seminar
- Computer Laboratory Systems Research Group Seminar
- Department of Computer Science and Technology talks and seminars
- Interested Talks
- Lecture Theatre 1, Computer Laboratory, William Gates Builiding
- ndk22's list
- ob366-ai4er
- rp587
- School of Technology
- Trust & Technology Initiative - interesting events
- yk449
Note: Ex-directory lists are not shown.
![[Talks.cam]](/static/images/talkslogosmall.gif)


Tuesday 26 February 2008, 15:30-16:00