Xen Summit: Running Xen without Direct Map


This talk was given by Hongyan Xia & David Woodhouse of Amazon at the 2020 Xen Project Developer and Design Summit.

With the rising number of speculation vulnerabilities in CPUs, it is time we rethink the design of Xen and restrict the attack surface as much as possible to defend against potential vulnerabilities in the future (defense-in-depth). At this year’s Xen Summit, Hongyan Xia & David Woodhouse from  Amazon, took viewers through ways to do this.

At the 2019 Xen Summit,  Secret-Free hypervisor was proposed and provided a roadmap for the goal.

In this talk, we hear about one of the two major goals, direct map removal,  and how it has been achieved in Xen.

Learn more about the steps necessary to remove the direct map, and how this can be achieved in a practical and much less intrusive way. Running Xen without Direct Map results in the ability to remove a major attack surface with negligible performance impact.

Check out the full presentation:

https://www.youtube.com/watch?v=RKJOwIkCnB4&list=PLYyw7IQjL-zFYmEoZEYswoVuXrHvXAWxj&index=5

 

 

Read more

Welcome Honda to the Xen Project Board
12/09/2024

We're excited to announce our newest Advisory Board Member Honda, to Xen Project. Since its foundation, Honda has been committed to "creating a society that is useful to people" by utilizing its technologies and ideas. Honda also focuses on environmental responsiveness and traffic safety, and continue

Say hello to our new website
12/05/2024

Hello Xen Community, You may have noticed something different... We've refreshed our existing website! Why did we do this? Well, all these new changes are part of an ongoing effort to increase our visibility and make it easier to find information on pages. We know how important it

Xen Project Announces Performance and Security Advancements with Release of 4.19
08/05/2024

New release marks significant enhancements in performance, security, and versatility across various architectures.  SAN FRANCISCO – July 31st, 2024 – The Xen Project, an open source project under the Linux Foundation, is proud to announce the release of Xen Project 4.19. This release marks a significant milestone in enhancing performance, security,

Upcoming Closure of Xen Project Colo Facility
07/10/2024

Dear Xen Community, We regret to inform you that the Xen Project is currently experiencing unexpected changes due to the sudden shutdown of our colocated (colo) data center facility by Synoptek. This incident is beyond our control and will impact the continuity of OSSTest (the gating Xen Project CI loop)