Kernel information integrity inspection
In some examples, a bus device includes a device controller to perform input/output (I/O) virtualization to provide a virtualized instance of the bus device. The device controller establishes a channel between the virtualized instance of the bus device and a guest operating system (OS) of a virtual machine (VM). The device controller receives, from the VM, address information relating to a portion of a memory containing information associated with a kernel of the guest OS, and obtains, for integrity inspection, the information associated with the kernel from the memory based on the address information.
1 . A bus device comprising:
an interface to a bus coupled to a processing resource that executes a virtual machine (VM); and
a device controller to:
perform input/output (I/O) virtualization to provide a virtualized instance of the bus device;
establish a channel between the virtualized instance of the bus device and a quest operating system (OS) of the VM;
receive, from the VM, address information relating to a portion of a memory containing information associated with a kernel of the quest OS; and
obtain, for integrity inspection, the information associated with the kernel from the memory based on the address information;
provide the information associated with the kernel obtained from the memory based on the address information to an inspector VM executed by the processing resource or another processing resource;
receive a request from the inspector VM for retrieval of the information associated with the kernel from a virtual memory of the VM; and
in response to the request, obtain the information associated with the kernel from the virtual memory, and provide, to the inspector VM, the information associated with the kernel, and
wherein the inspector VM is a privileged I/O virtualization endpoint with a privilege to request the retrieval of the information associated with the kernel from the virtual memory, and wherein another VM executed by the processing resource is without any privilege to request the retrieval of the information associated with the kernel from the virtual memory.
2 . The bus device of claim 1 , wherein the virtualized instance of the bus device is coupled over the channel with the VM without interception or interposition by a hypervisor.
3 . The bus device of claim 1 , wherein the I/O virtualization comprises Single Root I/O Virtualization (SRIOV) or Scalable I/O Virtualization (SIOV).
4 . The bus device of claim 1 , wherein the processing resource executes a plurality of VMs, and wherein the device controller is to perform the I/O virtualization to provide a plurality of virtualized instances of the bus device, each virtualized instance of the plurality of virtualized instances to interact with a respective VM of the plurality of VMs to perform integrity inspection of a kernel in the respective VM.
5 . The bus device of claim 1 , wherein the device controller is to perform the integrity inspection of the information associated with the kernel obtained from the memory based on the address information.
6 . The bus device of claim 1 , wherein the address information from the VM is provided by the VM upon booting of the VM.
7 . The bus device of claim 1 , wherein the virtualized instance of the bus device is to obtain the information associated with the kernel by direct memory access (DMA) from the memory.
8 . A bus device comprising:
an interface to a bus coupled to a processing resource that executes a virtual machine (VM); and
a device controller to:
perform input/output (I/O) virtualization to provide a virtualized instance of the bus device;
establish a channel between the virtualized instance of the bus device and a guest operating system (OS) of the VM;
receive, from the VM, address information relating to a portion of a memory containing information associated with a kernel of the quest OS; and
obtain, for integrity inspection, the information associated with the kernel from the memory based on the address information;
provide the information associated with the kernel obtained from the memory based on the address information to an inspector VM executed by the processing resource or another processing resource;
receive a request from the inspector VM for retrieval of the information associated with the kernel from a virtual memory of the VM;
in response to the request, obtain the information associated with the kernel from the virtual memory, and provide, to the inspector VM, the information associated with the kernel, and
provide, to the inspector VM, an identity of the VM and the address information relating to the portion of the memory containing the information associated with the kernel of the guest OS,
wherein the request from the inspector VM is based on the identity of the VM and the address information.
9 . The bus device of claim 8 , wherein the virtualized instance of the bus device is coupled over the channel with the VM without interception or interposition by a hypervisor.
10 . The bus device of claim 8 , wherein the I/O virtualization comprises Single Root I/O Virtualization (SRIOV) or Scalable I/O Virtualization (SIOV).
11 . The bus device of claim 8 , wherein the processing resource executes a plurality of VMs, and wherein the device controller is to perform the I/O virtualization to provide a plurality of virtualized instances of the bus device, each virtualized instance of the plurality of virtualized instances to interact with a respective VM of the plurality of VMs to perform integrity inspection of a kernel in the respective VM.
12 . The bus device of claim 8 , wherein the device controller is to perform the integrity inspection of the information associated with the kernel obtained from the memory based on the address information.
13 . A bus device comprising:
an interface to a bus coupled to a processing resource that executes a virtual machine (VM); and
a device controller to:
perform input/output (I/O) virtualization to provide a virtualized instance of the bus device;
establish a channel between the virtualized instance of the bus device and a guest operating system (OS) of the VM;
receive, from the VM, address information relating to a portion of a memory containing information associated with a kernel of the quest OS; and
obtain, for integrity inspection, the information associated with the kernel from the memory based on the address information,
wherein the device controller is to provide the information associated with the kernel obtained from the memory based on the address information to an inspector VM executed by the processing resource or another processing resource,
wherein the information associated with the kernel is provided in encrypted form to the inspector VM,
wherein the information associated with the kernel obtained from the memory is encrypted using a first encryption key, and wherein the device controller is to:
receive a decrypted version of the information associated with the kernel obtained from the virtual memory after a decryption of the encrypted information associated with the kernel; and
transmit the decrypted version of the information associated with the kernel wherein the decrypted version of the information is encrypted by a memory controller to produce the encrypted form of the information associated with the kernel that is provided to the inspector VM.
14 . The bus device of claim 13 , wherein the encrypting of the decrypted version of the information associated with the kernel uses a second encryption key different from the first encryption key.
15 . The bus device of claim 13 , wherein the virtualized instance of the bus device is coupled over the channel with the VM without interception or interposition by a hypervisor.
16 . The bus device of claim 13 , wherein the I/O virtualization comprises Single Root I/O Virtualization (SRIOV) or Scalable I/O Virtualization (SIOV).
17 . The bus device of claim 13 , wherein the processing resource executes a plurality of VMs, and wherein the device controller is to perform the I/O virtualization to provide a plurality of virtualized instances of the bus device, each virtualized instance of the plurality of virtualized instances to interact with a respective VM of the plurality of VMs to perform integrity inspection of a kernel in the respective VM.
18 . The bus device of claim 13 , wherein the device controller is to perform the integrity inspection of the information associated with the kernel obtained from the memory based on the address information.