Xen and the art of hypervisor introspection: Bitdefender donates meditative tech to open-source virty outfit
(2020/07/30)
- Reference: 1596117668
- News link: https://www.theregister.co.uk/2020/07/30/bitdefender_open_sources_to_xen_project/
- Source link:
Security vendor Bitdefender has open-sourced its hypervisor introspection technology, which the Xen Project will adopt as a sub-project.
Hypervisor introspection (HVI) makes it possible to inspect the memory of a guest VM, a desirable thing to do if you are hunting for malware infections in the guest.
Xen and Bitdefender have collaborated around this sort of thing [1]since at least 2015 when the open-source hypervisor added a feature, libbdvmi , that Bitdefender helped to develop. Citrix and Bitdefender later [2]commercialised the technology in Citrix's version of Xen.
Now Bitdefender and Xen have decided the best way to advance the tech is as an open-source project. The security vendor has also donated its Napoca "thin hypervisor" to the Xen Project. Napoca virtualizes CPU and memory, not hardware, and can therefore allow hypervisor introspection to happen on machines that don't run a full hypervisor.
"We are excited to see the range of uses the community will come up with for the technology, and fully expect to see HVI and Napoca technology used in areas beyond the scope of Bitdefender's security-focused purposes," said Bitdefender director of strategic alliances Shaun Donaldson.
Citrix's chief security strategist, Kurt Roemer, also welcomed the decision.
"Now that the technology is open source, the use cases to which HVI can be applied will result in direct value realised by both security teams and their businesses – especially for emergent threats," Roemer said.
The Xen Project already operates seven [3]teams that work on what the operation calls "sub-projects". As that term has been used to describe HVI, it appears the Project will now have an additional team.
The project has put more effort into embedded applications in recent years and the computers likely to run Xen in such situations could often benefit from enhanced security, or the lighter approach to virtualization offered by Napoca. ®
Get our [4]Tech Resources
[1] https://www.theregister.com/2015/08/05/xen_hardens_up_with_zerofootprint_guest_introspection_code/
[2] https://www.theregister.com/2017/02/10/citrix_bitdefender_in_xenonly_virtual_security_doubleteam/
[3] https://xenproject.org/developers/teams/
[4] https://whitepapers.theregister.com/
Hypervisor introspection (HVI) makes it possible to inspect the memory of a guest VM, a desirable thing to do if you are hunting for malware infections in the guest.
Xen and Bitdefender have collaborated around this sort of thing [1]since at least 2015 when the open-source hypervisor added a feature, libbdvmi , that Bitdefender helped to develop. Citrix and Bitdefender later [2]commercialised the technology in Citrix's version of Xen.
Now Bitdefender and Xen have decided the best way to advance the tech is as an open-source project. The security vendor has also donated its Napoca "thin hypervisor" to the Xen Project. Napoca virtualizes CPU and memory, not hardware, and can therefore allow hypervisor introspection to happen on machines that don't run a full hypervisor.
"We are excited to see the range of uses the community will come up with for the technology, and fully expect to see HVI and Napoca technology used in areas beyond the scope of Bitdefender's security-focused purposes," said Bitdefender director of strategic alliances Shaun Donaldson.
Citrix's chief security strategist, Kurt Roemer, also welcomed the decision.
"Now that the technology is open source, the use cases to which HVI can be applied will result in direct value realised by both security teams and their businesses – especially for emergent threats," Roemer said.
The Xen Project already operates seven [3]teams that work on what the operation calls "sub-projects". As that term has been used to describe HVI, it appears the Project will now have an additional team.
The project has put more effort into embedded applications in recent years and the computers likely to run Xen in such situations could often benefit from enhanced security, or the lighter approach to virtualization offered by Napoca. ®
Get our [4]Tech Resources
[1] https://www.theregister.com/2015/08/05/xen_hardens_up_with_zerofootprint_guest_introspection_code/
[2] https://www.theregister.com/2017/02/10/citrix_bitdefender_in_xenonly_virtual_security_doubleteam/
[3] https://xenproject.org/developers/teams/
[4] https://whitepapers.theregister.com/
Re: How much can VPS hosters see in your memory?
sysconfig
It's been a while since I set up Xen-based clusters. But from the top of my head I'd say, yes, in theory. The fact that Bitdefender's toolkit would add ability to analyse your VM's memory for malware, supports that.
If data is so sensitive that not even the hosting company must ever be able to read it, don't use it in someone else's hypervisor (or indeed on their hardware).
How much can VPS hosters see in your memory?
This suddenly got me thinking. If you run a VPS but use on-disk encryption (using GELI or ZFS native encryption) your hoster can't read the disk. But, how much access do they have to your memory? Could they lift the GELI encryption key from your RAM? How much else can they see?