[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xen-users] malicious paravirtualized guests: security and isolation


  • To: xen-users@xxxxxxxxxxxxxxxxxxx
  • From: "Vasiliy Baranov" <vasiliy.baranov@xxxxxxxxx>
  • Date: Thu, 6 Nov 2008 16:15:24 +0300
  • Delivery-date: Thu, 06 Nov 2008 05:16:06 -0800
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:mime-version:content-type; b=PUkEppXodO4DWy1OF2Eia8e1ayQpztxvaU69yPUwstPOLS1BdhaXae0PXnbAATzENO qyx7yICS3RcmRFCvRXNdaXFGOAVDME913K18g/SLzHkKw7f0oZn20kBj2Y9KhFX+xMC6 /c1QAEjiIzQYhymTUM0qzNmX/ucZ3Vu/hKj48=
  • List-id: Xen user discussion <xen-users.lists.xensource.com>

Hi,

I have a question about isolation and security guarantees Xen provides, if any, in cases when domU guests are not completely trusted, that is, can be malicious. Right now I am specifically interested in the scenario where all guests are paravirtualized, but HVM case is of some interest too.

Say, I want to let my users run their own guests on a Xen host that I own. Users will bring their own disk images. I don't completely trust my users. Does the use of Xen guarantees that malicious guests will be unable to harm other guests or the entire host in any way (for example, kill the entire host)? It is interesting to know both what is guaranteed in theory (that is, if Xen and dom0 work as designed) and how things go in practice.

If I disallow users to use their kernels, that is, if I run guests with my own kernel(s) only, will that improve the situation? How about loadable kernel modules? If I allow Linux guests to load their custom kernel modules, will that nullify the effect of using trusted kernels?

I currently use Xen 3.1.4, if that matters.

Thank you very much in advance,
Vasiliy
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.