EDBT 2026 Demo / reviewers in the wild / expert
Kenichi Kourai
dblp:27/46
· DBLP profile ↗
42ranked-venue papers
15as first author
13since 2021 · last 2025
0000-0002-5455-4418ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 16 · 2 first-author · 7 since 2021Software engineering, systems software and programming languages · 14 · 4 first-author · 5 since 2021Security and privacy · 12 · 5 first-author · 4 since 2021Systems, architecture and hardware · 6 · 4 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Secure Privacy Control inside Clouds with AMD SEV and Nested VirtualizationabstractThe leakage of personal data from public clouds has been a major issue in recent years. As cloud services become increasingly complex, e.g., using microservices and multicloud, personal data can be distributed to various services. However, the details of data flow inside clouds are not disclosed to users. Therefore, users cannot know how their personal data is processed and stored. To regain control of personal data, users need a privacy control mechanism for clouds, but the mechanism provided by clouds cannot be trusted. This paper proposes SEV-tracker for enabling secure privacy control inside clouds using a processor-based trusted execution environment (TEE). SEV-tracker injects a user hypervisor into a cloud virtual machine (VM). Using nested virtualization, the user hypervisor runs a cloud service in a user VM created on top of it and tracks and controls the data flow of the service. To mutually protect the user hypervisor and the cloud from each other, SEV-tracker applies AMD SEV to both VMs. We have implemented SEV-tracker using BitVisor as a lightweight user hypervisor and unikernels as cloud services to mitigate the overhead of nested virtualization. We conducted several experiments and examined the effectiveness of SEV-tracker. Naoya Ando, Kazuki Takiguchi, Kenichi Kourai |
COMPSAC | 3 |
| 2025 | Keyspector: Secure Monitoring of IoT Devices Using RISC-V KeystoneabstractThe Internet of Things (IoT) devices have become increasingly widespread in recent years. Since IoT devices tend to suffer from attacks from the Internet, they need monitoring using intrusion detection systems (IDS). However, IDS running inside a target system can be easily disabled by intruders. To address this issue, several approaches have been proposed to securely execute IDS using trusted execution environments (TEEs) such as Intel SGX and Arm TrustZone. Nevertheless, existing approaches have several drawbacks, e.g., substantial overhead for accessing the memory of the target system and too high privileges to execute IDS. This paper proposes Keyspector for enabling the secure execution of IDS using Keystone, which is a TEE for RISC- V processors. Keyspector executes IDS inside a secure execution environment called an enclave, which has relatively low privileges. For efficient monitoring, it enables only an enclave running IDS to share the memory of the target system using the security monitor running below the system. Using the shared memory, IDS can directly monitor the data of the target system. We have implemented Keyspector in the security monitor and the Eyrie runtime and confirmed that the overhead of the IDS running in an enclave was 10%, compared with the traditional IDS. Takahito Iwano, Kenichi Kourai |
PRDC | 2 |
| 2025 | TZmediator: Secure Cooperative Execution of Cloud Applications Using POSIX APIs on Arm TrustZoneabstractEdge computing enables clouds to execute their applications closer to end-users. Even on untrusted edge devices, Arm TrustZone can securely run cloud applications in the secure world as trusted applications (TAs). Since the secure world has too high privileges, vulnerabilities in cloud applications could lead to the compromise of the entire system. To minimize the attack surface, it is desirable to run security-insensitive tasks in the normal world as unprivileged client applications (CAs). However, cooperation between CAs and TAs requires the use of the APIs specialized for TrustZone, which prevents flexible interactions. This paper proposes TZmediator to enable cooperative execution using standard POSIX APIs for a cloud application partitioned into two worlds. For inter-world seamless communications, TZmediator creates a shadow process in the normal world for each TA and delegates the invocation of POSIX APIs by a TA to the shadow process. Currently, it supports the message passing APIs, the shared memory API, and the signal API. If users require stronger isolation, TZmediator can execute security -sensitive tasks in TAs using WebAssembly. We have implemented TZmediator on OP- TEE and examined communication performance between CAs and TAs. Taiyo Sato, Kenichi Kourai |
PRDC | 2 |
| 2024 | An Efficient State-Saving Mechanism for Out-of-Band Container MigrationabstractMany clouds provide containers as lightweight virtu-alized environments inside virtual machines (VMs). Containers can be migrated between source and destination VMs for vari-ous reasons such as load balancing. However, the performance of container migration is largely degraded by the load and vir-tualization overhead of VMs because the migration mechanism runs inside VMs. Conversely, the performance of containers is largely affected by the load of container migration. This paper proposes OVmigrate to enable out-of-band container migration, which migrates a container running inside a VM from the outside of the VM. OVmigrate analyzes and obtains the states of a container in the memory of the source VM using a technique called VM introspection. It enables the migration mechanism outside a VM to independently save the states of a container running inside the VM. We have implemented OVmigrate for Linux and KVM and compared the performance of state saving with the existing tool called CRIU running inside the VM. Yuki Asakura, Kenichi Kourai |
CloudCom | 2 |
| 2024 | Parallel and consistent live checkpointing and restoration of split-memory VMsabstractRecently, clouds provide virtual machines (VMs) with a large amount of memory for big data analysis. For easier migration of such VMs, split migration divides the memory of a VM into several fragments and transfers them to multiple hosts. Since the migrated VM called a split-memory VM needs to exchange memory data between the hosts using remote paging , it is inherently subject to host and network failures. As a countermeasure, the checkpoint/restore mechanism has been used to periodically save the state of a VM, but the traditional mechanism is not suitable for split-memory VMs. It has to move a large amount of memory data between hosts during checkpointing and can just restore a normal VM on one host. This paper proposes D-CRES for enabling efficient checkpointing and restoration of split-memory VMs. D-CRES achieves fast checkpointing by saving the memory of a split-memory VM at all hosts in parallel without remote paging. It supports consistent live checkpointing to save the memory of a running VM by considering remote paging caused by the VM itself during checkpointing. In addition, it can incrementally take a checkpoint by considering remote paging since the last checkpointing. Upon failure, D-CRES restores a split-memory VM at multiple hosts in parallel . We have implemented D-CRES in KVM and showed that live checkpointing in D-CRES was up to 39x faster than the traditional mechanism. Tokito Murata, Kenichi Kourai |
Future Gener. Comput. Syst. | 2 |
| 2023 | Reliable and Accurate Fault Detection with GPGPUs and LLVMabstractAs the scale and complexity of cloud systems are increasing, system faults are becoming unavoidable. Therefore, they should be detected as reliably and accurately as possible. Black-box monitoring can reliably monitor a target system from a remote host, but it is often coarse-grained and cannot identify the root causes of system faults. In contrast, white-box monitoring can accurately obtain fault information inside a target system, but it is largely affected by system faults. This paper proposes GPUSentinel for more reliable white-box monitoring using general-purpose GPUs. GPUSentinel runs fault detectors in an isolated GPU, which is not easily affected by faults of a target system. For accurate detection, fault detectors in a GPU analyze main memory and directly monitor the state of the operating system. To easily develop such fault detectors, GPUSentinel provides a development environment with LLVM. We have implemented GPUSentinel and seven fault detectors and then confirmed that GPUSentinel could detect various system faults and identify the root causes. Yuichi Ozaki, Sousuke Kanamoto, Hiroaki Yamamoto, Kenichi Kourai |
CLOUD | 4 |
| 2023 | Memory-virtualizing and -devirtualizing VM Migration with Private Virtual MemoryabstractRecently, Infrastructure-as-a-Service clouds provide virtual machines (VMs) with a large amount of memory. Such large-memory VMs can be migrated to other hosts, but it is costly to always preserve hosts with sufficient memory as the destinations of VM migration. Instead, memory-virtualizing VM migration using virtual memory is possible, but the performance of VM migration and migrated VMs largely degrades because traditional virtual memory causes excessive paging during and after VM migration. This paper proposes VMemDirect, which achieves efficient memory-virtualizing VM migration. VMemDirect provides private virtual memory with private swap space on an NVMe SSD for each VM. Then, it directly transfers the memory data of a VM to either physical memory or private swap space to completely avoid paging during VM migration. In addition, VMemDirect provides efficient memory-devirtualizing VM migration for VMs running on private virtual memory. To optimize the performance of migrated VMs, it uses a more accurate and efficient LRU approximation using chunk queues and performs asynchronous paging. We showed that VMemDirect dramatically improved the performance of VM migration and migrated VMs using large VMs. Yuji Muraoka, Kenichi Kourai |
COMPSAC | 2 |
| 2023 | SEmigrate: Optimizing Data Protection with VM IntrospectionabstractRecently, virtual machines (VMs) with a large amount of memory are widely used. Since it is often difficult to migrate such a large-memory VM to one large destination host, split migration divides the memory of a VM into small fragments and transfers them to multiple destination hosts. The migrated VM exchanges its memory data between the hosts using remote paging. To prevent information leakage from and tampering with the memory data in an untrusted environment, memory encryption and integrity checking can be used. However, the overhead of such data protection affects the performance of the hosts and the VM more largely in faster networks. This paper proposes SEmigrate for optimizing data protection in split migration and remote paging. SEmigrate avoids decrypting memory data and integrity checking at most of the destination hosts to reduce the protection overhead and completely prevent information leakage. Also, it can selectively encrypt only sensitive memory data and check the integrity of only important memory data by analyzing the memory of the guest operating system and applications in a VM. SEmigrate could reduce the time for data-protected split migration by up to 43% and improve the performance of migrated VMs by up to 19% in 100 Gigabit Ethernet. Shuhei Horio, Kouta Takahashi, Kenichi Kourai |
PRDC | 3 |
| 2023 | SSdetector: Secure and Manageable Host-based IDS with SGX and SMMabstractHost-based intrusion detection systems (HIDS) are used to monitor the internals of target systems. It is essentially difficult to execute HIDS securely inside target systems. For example, it is not guaranteed that HIDS can obtain correct information from compromised systems. If HIDS is tampered with by intruders, it would be easily disabled. So far, various techniques have been proposed to securely execute HIDS using the security features of processors, e.g., System Management Mode (SMM) and SGX in Intel processors. However, strongly secure HIDS sacrifices its manageability, whereas manageable HIDS is less secure. In practice, it is important to achieve not only the security but also the manageability of HIDS. This paper proposes SSdetector for achieving both security and manageability by combining SGX and SMM. SSdetector securely runs HIDS inside an SGX enclave, which is a protected region inside an SGX application. Since HIDS is developed as an SGX application, the management of HIDS is easier. To securely obtain system information in memory, in-enclave HIDS invokes the SMM monitor running in an isolated execution environment created by BIOS. SSdetector protects information passed between in-enclave HIDS and the SMM monitor by encryption and integrity checking. We have implemented SSdetector in UEFI BIOS and examined the performance of HIDS collecting system information necessary for the proc filesystem. Yoshimichi Koga, Kenichi Kourai |
TrustCom | 2 |
| 2022 | Secure Offloading of User-level IDS with VM-compatible OS Emulation Layers for Intel SGXabstractSince virtual machines (VMs) provided by Infrastructure-as-a-Service clouds often suffer from attacks, they need to be monitored using intrusion detection systems (IDS). For secure execution of host-based IDS (HIDS), IDS offloading is used to run IDS outside target VMs, but offloaded IDS can still be attacked. To address this issue, secure IDS offloading using Intel SGX has been proposed. However, IDS development requires kernel-level programming, which is difficult for most IDS developers. This paper proposes SCwatcher for enabling user-level HIDS running on top of the operating system (OS) to be securely offloaded using VM-compatible OS emulation layers for SGX. SCwatcher provides the standard OS interface used in a target VM to in-enclave IDS. Especially, the virtual proc filesystem called vProcFS analyzes OS data using VM introspection and returns the system information inside the target VM. We have implemented SCwatcher using Xen supporting SGX virtualization and two types of OS emulation layers for SGX called SCONE and Occlum. Then, we confirmed that SCwatcher could offload legacy HIDS and showed that the performance could be comparable to insecure IDS offloading. Takumi Kawamura, Kenichi Kourai |
CLOUD | 2 |
| 2021 | Secure Offloading of Intrusion Detection Systems from VMs with Intel SGXabstractVirtual machines (VMs) inside clouds need to be monitored using intrusion detection systems (IDS). Since host-based IDS can be easily disabled by intruders, IDS offloading with VM introspection (VMI) is used to securely run IDS outside a target VM. However, offloaded IDS can be still attacked because it runs on top of a vulnerable operating system (OS). Various systems have been proposed to protect offloaded IDS, but no systems provide an appropriate execution environment to IDS. This paper proposes SGmonitor for enabling the secure execution of IDS offloaded from VMs inside clouds using Intel SGX. SGmonitor executes IDS in SGX enclaves and preserves confidentiality and integrity. It provides secure VMI for memory and storage by using encryption and integrity checking. To make the development of offloaded IDS easier, it provides the in-kernel API to in-enclave IDS and enables transparent access to OS data in VMs. We have implemented SGmonitor in Xen with SGX support and showed that the overhead of in-enclave IDS was 31% in compensation for much stronger security. Tomoharu Nakano, Kenichi Kourai |
CLOUD | 2 |
| 2021 | Optimizing VMs across Multiple Hosts with Transparent and Consistent Tracking of Unused MemoryabstractRecently, Infrastructure-as-a-Service (IaaS) clouds provide virtual machines (VMs) with a large amount of memory. To make the migration of such large-memory VMs flexible, split migration has been proposed. It divides the memory of a VM into smaller pieces and transfers them to multiple destination hosts. After the migration, the VM runs across multiple hosts and its memory data is exchanged between hosts by remote paging. There is often unused memory in a large-memory VM, but data of even unused memory is transferred via the network. This paper proposes FCtrans to achieve efficient split migration and remote paging by considering unused memory. FCtrans avoids transferring data of unused memory to destination hosts on split migration. Similarly, it does not perform remote paging for unused memory and immediately continues the execution of the VM. To enable this, FCtrans keeps track of the memory usage of a VM after starting split migration. In addition, it transparently and consistently reclaims memory released after used by the guest operating system using VM introspection and deals with it as unused. We have implemented FCtrans in KVM and conducted experiments using a VM with 352 GB of memory on the StarBED testbed. It is shown that split migration became up to 29x faster and the memory access performance of a VM across multiple hosts improved by up to 85 %. Soichiro Tauchi, Kenichi Kourai, Lukman Ab. Rahim |
CLOUD | 2 |
| 2021 | Improvement of ARC Considering Negative Locality of Reference in Virtualized EnvironmentabstractIn a virtualized environment using virtual computers, a two-level cache hierarchy for accessing storage devices is constructed, which consists of a host OS cache and a guest OS cache. In such an environment, if the upper cache (guest OS cache) uses LRU as a cache replacement algorithm, it is known that negative temporal locality of reference occurs in the lower cache (host OS cache). Naomichi Fukuda, Kenichi Kourai, Saneyasu Yamaguchi |
IEEE BigData | 2 |
| 2020 | Flexible and Efficient Partial Migration of Split-memory VMsabstractRecently, virtual machines (VMs) with a large amount of memory are being widely used. For flexible migration of such large-memory VMs without large hosts, split migration has been proposed. It transfers VM fragments to multiple smaller hosts and runs a split-memory VM across those hosts with remote paging. However, the traditional method cannot migrate a split-memory VM efficiently because it always migrates the entire VM. In addition, it has to gather all the VM fragments to one host and transfer them from that host. To address these issues, this paper proposes flexible and efficient partial migration of split-memory VMs. In particular, subst migration migrates only part of a split-memory VM to enable the maintenance of some of the hosts running the VM. Merge migration efficiently consolidates VM fragments distributed across multiple hosts into one host by directly transferring a VM fragment from each host. Even if a split-memory VM itself causes remote paging during such partial migration, the consistency of the VM is maintained by retransferring and invalidating target memory. We have implemented partial migration in KVM and showed its efficiency. Takahiro Kashiwagi, Kenichi Kourai |
CLOUD | 2 |
| 2020 | VM Migration for Secure Out-of-band Remote Management with Nested VirtualizationabstractInfrastructure-as-a-Service clouds provide out-of-band remote management of the systems in virtual machines (VMs). This management method enables users to manage their systems even on several types of failures inside VMs. In this method, users access virtual devices of their VMs, but virtual devices are not sufficiently protected against untrusted cloud operators. For secure out-of-band remote management, previous work securely runs shadow devices outside an untrusted virtualized system using nested virtualization. However, the states of shadow devices are lost during VM migration. In this paper, we propose USShadow for continuing secure out-of-band remote management after VM migration. USShadow enables the migration manager inside the virtualized system to transparently and securely save and restore the states of shadow devices outside it. We have implemented USShadow, which supports Xen and KVM as virtualized systems. Then, we confirmed that USShadow could continue virtual serial console and that the migration overhead was negligible. Tomoya Unoki, Kenichi Kourai |
CLOUD | 2 |
| 2020 | Cache Management with Fadvise Based on LFUabstractVirtualization is used for various purposes such as cloud computing and a virtualized environment has been one of the most important platforms. In many virtualized environments, access to its persistent storage device, e.g. hard disk drive (HDD) or solid-state drive (SSD), is performed via two caches, which are page caches of guest and host operating systems. Both caches are usually managed based on the least recently used (LRU) algorithm. Previous work demonstrated that accesses to the host operating system page cache have a negative temporal locality of reference in these cases. Namely, an accessed block will probably not be accessed again in the near future. This locality severely decreases the hit ratio of a host operating system page cache. For addressing this issue, a method for improving the locality of reference in the accesses in the host operating system page cache by fixing data stored in the guest operating system page cache was proposed. However, the method assumed that the hot spot, which is the data area aggressively accessed, was given. Because of this limitation, the method can rarely be used. In this paper, we propose a method for improving the hit ratio of a host operating system page cache by enhancing the locality of reference at the cache. First, we explain the negative temporal locality of reference in virtualized environments. Second, we propose a method for enhancing the locality of reference in the host operating system page cache for improving its hit ratio without an assumption that its hotspot is given. This method observes file accesses in the system using an operating system kernel function and automatically detects the hotspot. This then stores the area in the guest operating system page cache. As a result, the locality of reference in the host operating system cache increases. Lastly, we evaluate this proposed method, then show that this method outperforms the normal method and can provide comparable performance with an existing method even if the hot spot is not given. Naomichi Fukuda, Taisei Miura, Kenichi Kourai, Saneyasu Yamaguchi |
COMPSAC | 3 |
| 2020 | Optimization of Parallel Applications Under CPU OvercommitmentabstractAs cloud computing is widely used, even parallel applications run in virtual machines (VMs) of clouds. When CPU overcommitment is performed in clouds, physical CPU cores (pCPUs) can become less than virtual CPUs (vCPUs). In such a situation, it is reported that application performance degrades more largely than expected by the decrease of pCPUs available to each VM. To address this issue, several researchers have proposed optimization techniques of reducing the number of vCPUs assigned to each VM. However, their effectiveness is confirmed only in a limited VM configuration. In this paper, we have first investigated application performance under three configurations and revealed that the previous work cannot always achieve optimal performance. Then we propose pCPU-Est for improving application performance under CPU overcommitment. pCPU-Est dynamically optimizes the number of vCPUs on the basis of correlation between CPU utilization and execution time (dynamic vCPU optimization). In addition, it dynamically optimizes the number of application threads when possible (thread optimization). According to our experiments, dynamic vCPU optimization improved application performance by up to 42%, while thread optimization did by up to 72x. Tokiko Takayama, Kenichi Kourai |
COMPSAC | 2 |
| 2020 | Transparent IDS Offloading for Split-Memory Virtual MachinesabstractTo enable virtual machines (VMs) with a large amount of memory to be flexibly migrated, split migration has been proposed. It divides a large-memory VM into small pieces and transfers them to multiple hosts. After the migration, the VM runs across those hosts and exchanges memory data between hosts using remote paging. For such a split-memory VM, however, it becomes difficult to securely run intrusion detection systems (IDS) outside the VM using a technique called IDS offloading. This paper proposes VMemTrans to support transparent IDS offloading for split-memory VMs. In VMemTrans, offloaded IDS can monitor a split-memory VM as if that memory were not distributed. To achieve this, VMemTrans enables IDS running in one host to transparently access VM's remote memory. To consider a trade-off, it provides two methods for obtaining memory data from remote hosts: self paging and proxy paging. We have implemented VMemTrans in KVM and compared the execution performance between the two methods. Kouki Yamato, Kenichi Kourai, Tarek N. Saadawi |
COMPSAC | 2 |
| 2020 | Virtual Machine Introspection for Anomaly-Based Keylogger DetectionabstractSoftware Keyloggers are dominant class of malicious applications that surreptitiously logs all the user activity to gather confidential information. Among many other types of keyloggers, API-based keyloggers can pretend as unprivileged program running in a user-space to eavesdrop and record all the keystrokes typed by the user. In a Linux environment, defending against these types of malware means defending the kernel against being compromised and it is still an open and difficult problem. Considering how recent trend of edge computing extends cloud computing and the Internet of Things (IoT) to the edge of the network, a new types of intrusion-detection system (IDS) has been used to mitigate cybersecurity threats in edge computing. Proposed work aims to provide secure environment by constantly checking virtual machines for the presence of keyloggers using cutting edge artificial immune system (AIS) based technology. The algorithms that exist in the field of AIS exploit the immune system's characteristics of learning and memory to solve diverse problems. We further present our approach by employing an architecture where host OS and a virtual machine (VM) layer actively collaborate to guarantee kernel integrity. This collaborative approach allows us to introspect VM by tracking events (interrupts, system calls, memory writes, network activities, etc.) and to detect anomalies by employing negative selection algorithm (NSA). Huseyn Huseynov, Kenichi Kourai, Tarek N. Saadawi, Obinna Igbe |
HPSR | 2 |
| 2020 | Flexible service consolidation with nested virtualization and library operating systemsabstractSummary In Infrastructure‐as‐a‐service (IaaS) clouds, users can reduce costs by scale‐in or scale‐down when running services are underutilized. Since these optimizations of instance deployment require at least one minimum instance even for running an underutilized service, cost reduction is limited. For further optimization, multiple services can be consolidated into one instance. However, services have to be stopped temporarily at the consolidation time, and isolation between services becomes weaker after the consolidation. To solve these problems, this paper proposes FlexCapsule, which enables seamless and secure service consolidation in existing IaaS clouds. FlexCapsule runs each service in a lightweight virtual machine (VM) called an app VM, using a library operating system. An app VM runs inside an instance using a technique called nested virtualization. FlexCapsule can optimize instance deployment with negligible downtime by flexibly migrating app VMs. Due to strong isolation provided by app VMs, it can guarantee security between consolidated services. In addition, FlexCapsule provides multiprocess support using app VMs by emulating process fork and process pools. We have implemented FlexCapsule in Xen using both fully virtualized OSv and paravirtualized MiniOS. Then, we examined the effectiveness of FlexCapsule using several applications. Due to the premature implementation of nested virtualization in Xen, the performance of app VMs largely degraded, but we believe that the performance could be improved using several existing optimizations. Kenichi Kourai, Kouta Sannomiya |
Softw. Pract. Exp. | 1 |
| 2018 | S-memV: Split Migration of Large-Memory Virtual Machines in IaaS CloudsabstractRecently, Infrastructure-as-a-Service clouds provide virtual machines (VMs) with a large amount of memory. Such large-memory VMs make VM migration difficult because it is costly to reserve large-memory hosts as the destination. Using virtual memory is a remedy for this problem, but virtual memory is incompatible with the memory access pattern in VM migration. Consequently, large performance degradation occurs during and after VM migration due to excessive paging. This paper proposes split migration of large-memory VMs with S-memV. Split migration migrates a VM to one main host and one or more sub-hosts. It divides the memory of a VM and transfers memory likely to be accessed to the main host. Since it transfers the rest of the memory directly to the sub-hosts, no paging occurs during VM migration. After split migration, remote paging is performed between the main host and the sub-hosts, but its frequency is lower thanks to memory splitting that is aware of remote paging. We have implemented S-memV in KVM and showed that the performance of split migration and application performance after VM migration were comparable to that of traditional VM migration with sufficient memory. Masato Suetake, Takahiro Kashiwagi, Hazuki Kizu, Kenichi Kourai |
IEEE CLOUD | 4 |
| 2018 | Secure Out-of-band Remote Management of Virtual Machines with Transparent PassthroughabstractInfrastructure-as-a-Service clouds provide out-of-band remote management for users to access their virtual machines (VMs). Out-of-band remote management is a method for indirectly accessing VMs via their virtual devices. While virtual devices running in the virtualized system are managed by cloud operators, not all cloud operators are always trusted in clouds. To prevent information leakage from virtual devices and tampering with their I/O data, several systems have been proposed by trusting the hypervisor in the virtualized system. However, they have various issues on security and management. This paper proposes VSBypass, which enables secure out-of-band remote management outside the virtualized system using a technique called transparent passthrough. VSBypass runs the entire virtualized system in an outer VM using nested virtualization. Then it intercepts I/O requests of out-of-band remote management and processes those requests in shadow devices, which run outside the virtualized system. We have implemented VSBypass in Xen for the virtual serial console and GUI remote access. We confirmed that information leakage was prevented and that the performance was comparable to that in traditional out-of-band remote management. Shota Futagami, Tomoya Unoki, Kenichi Kourai |
ACSAC | 3 |
| 2017 | Resource Cages: A New Abstraction of the Hypervisor for Performance Isolation Considering IDS OffloadingabstractSince Infrastructure-as-a-Service (IaaS) clouds contain many vulnerable virtual machines (VMs), intrusion detection systems (IDSes) should be run for all the VMs. IDS offloading is promising for this purpose in that it allows IaaS providers to run IDSes outside VMs without any cooperation of users. However, IDS offloading makes performance isolation between VMs difficult because IDSes offloaded from a VM consume resources outside the VM. As a result, the total resource usage of the VM and the offloaded IDSes exceeds the limits configured to the VM. In this paper, we propose a new abstraction of the hypervisor, called a resource cage. A resource cage can manage a VM and offloaded IDSes as a group and achieves performance isolation between resource cages, e.g., CPU limits, CPU shares, and memory limits. In addition to performance isolation, it keeps high resource utilization for a VM and offloaded IDSes as much as possible. We have implemented resource cages in Xen and KVM. Our experiments showed that resource cages could control the resource usage of a VM and offloaded IDSes effectively. Kenichi Kourai, Sungho Arai, Kousuke Nakamura, Seigo Okazaki, Shigeru Chiba |
CloudCom | 1 |
| 2017 | Secure IDS Offloading with Nested Virtualization and Deep VM Introspection
Shohei Miyama, Kenichi Kourai |
ESORICS (2) | 2 |
| 2016 | Secure Offloading of Legacy IDSes Using Remote VM Introspection in Semi-trusted CloudsabstractIn Infrastructure-as-a-Service (IaaS) clouds, intrusion detection systems (IDSes) increase their importance. To securely detect attacks against virtual machines (VMs), IDS offloading with VM introspection (VMI) has been proposed. In semi-trusted clouds, however, it is difficult to securely offload IDSes because there may exist insiders such as malicious system administrators. First, secure VM execution cannot coexist with IDS offloading although it has to be enabled to prevent information leakage to insiders. Second, offloaded IDSes can be easily disabled by insiders. To solve these problems, this paper proposes IDS remote offloading with remote VMI. Since IDSes can run at trusted remote hosts outside semi-trusted clouds, they cannot be disabled by insiders in clouds. Remote VMI enables IDSes at remote hosts to introspect VMs via the trusted hypervisor inside semi-trusted clouds. Secure VM execution can be bypassed by performing VMI in the hypervisor. Remote VMI preserves the integrity and confidentiality of introspected data between the hypervisor and remote hosts. The integrity of the hypervisor can be guaranteed by various existing techniques. We have developed RemoteTrans for remotely offloading legacy IDSes and confirmed that RemoteTrans could achieve surprisingly efficient execution of legacy IDSes at remote hosts. Kenichi Kourai, Kazuki Juda |
CLOUD | 1 |
| 2016 | Seamless and Secure Application Consolidation for Optimizing Instance Deployment in CloudsabstractIn Infrastructure-as-a-Service clouds, users can reduce costs by scale-in or-down when running applications are under-utilized. Since these optimizations of instance deployment require at least one minimum instance even for running an under-utilized application, cost reduction is limited. For further optimization, multiple applications can be consolidated into one instance. However, applications have to be stopped temporarily at the consolidation time and isolation between applications becomes weaker after the consolidation. To solve these problems, this paper proposes FlexCapsule, which enables seamless and secure application consolidation in existing IaaS clouds. FlexCapsule runs each application in a lightweight virtual machine (VM), called an app VM, using a library operating system. An app VM runs inside an instance using nested virtualization. Using VM migration, FlexCapsule can optimize instance deployment with negligible downtime. Thanks to strong isolation provided by app VMs, it guarantees security between consolidated applications. In addition, FlexCapsule provides multi-process support using app VMs such as process fork and process pools. We have implemented FlexCapsule using Xen and OSvand confirmed its effectiveness. Kenichi Kourai, Kouta Sannomiya |
CloudCom | 1 |
| 2016 | VMBeam: Zero-Copy Migration of Virtual Machines for Virtual IaaS CloudsabstractVirtual Infrastructure-as-a-Service (IaaS) clouds are emerging for secondary cloud service providers to manage their own IaaS clouds on top of existing IaaS clouds. In virtual IaaS clouds, guest virtual machines (VMs) run inside cloud VMs provided by existing IaaS clouds. Unlike traditional IaaS clouds, they can be migrated between cloud VMs co-located at the same host. However, the performance of such VM migration is low due to slow virtual networks and doubled system loads. To optimize VM migration between co-located cloud VMs, we propose zero-copy migration for virtual IaaS clouds. Zero-copy migration just relocates the memory image of a guest VM without any copy. To enable live migration with negligible downtime, it first makes the memory of a guest VM share with the destination cloud VM and thereafter completes memory relocation. We have implemented a system called VMBeam for enabling zero-copy migration in Xen. According to our experimental results, zero-copy migration could achieve high migration performance and low system loads. Kenichi Kourai, Hiroki Ooba |
SRDS | 1 |
| 2015 | Virtual AMT for Unified Management of Physical and Virtual DesktopsabstractTo reduce the burden of administrators in enterprises, current PCs are equipped with Intel Active Management Technology (AMT). AMT enables administrators to perform hardware-level remote management of desktops even on system failures. Recently, however, virtual desktops are emerging with virtual machines (VMs), e.g., In Desktop as a Service (DaaS). Since physical and virtual desktops are mixed in current enterprises, administrators have to manage them using two different tools: that for AMT and that for VMs. In this paper, we propose vAMT, which is virtual AMT for VMs. vAMT provides the same interfaces as AMT: WS-Management, SOAP, and KVM interfaces. Using AMT and vAMT, administrators can perform unified management of physical and virtual desktops without being aware of the differences in most of the operations. We have implemented vAMT and confirmed that the existing management tools for AMT could also manage virtual desktops. Kenichi Kourai, Kouki Oozono |
COMPSAC | 1 |
| 2015 | Host OS page cache hit ratio improvement based on guest OS page dropabstractIn a virtualized environment, such as a cloud computing environment, guest and host operating systems (OS) run simultaneously. Both of the operating systems have page caches for disk accesses. In such an environment, the second level cache does not work effectively because of negative temporal locality of access and duplicated storing in both the caches. In this paper, we propose a method for increasing the hit ratio of the host operating system page cache. The method monitors pages dropped from the guest operating system page cache and stores the pages into the host operating system cache. After the proposal, we introduce the design and implementation of our system. Our implementation aims to be applicable without modification to the hypervisor, and thus it can be applied for an environment with a proprietary hypervisor. Lastly, we present the evaluation of the hit ratio of the host operating system cache, and then demonstrate that our method can improve the cache hit ratio. Hiroki Sugimoto, Kenichi Kourai, Saneyasu Yamaguchi |
iiWAS | 2 |
| 2014 | Efficient VM Introspection in KVM and Performance Comparison with XenabstractIntrusion detection system (IDS) offloading is useful for securely executing IDSes. It runs a target system in a virtual machine (VM) and enables IDSes to monitor the VM from the outside using VM introspection. Although VM introspection is well studied, its performance has not been reported in detail. The performance becomes important when users choose virtualization software, e.g., Xen and KVM. However, the performance comparison is difficult because there is no efficient implementation of VM introspection in KVM. In this paper, we first propose KVMonitor for efficient VM introspection in KVM. Using KVMonitor, we have ported Transcall for offloading legacy IDSes. For memory introspection, KVMonitor was 32 times faster than the existing LibVMI. Then we present performance comparison between Xen and KVM on VM introspection. The experimental results showed that checking the kernel memory with KVMonitor was 118 times faster than that in Xen. Even for legacy chkrootkit, the execution time with KVMonitor was 63% shorter than that in Xen. Kenichi Kourai, Kousuke Nakamura |
PRDC | 1 |
| 2013 | Synchronized Co-migration of Virtual Machines for IDS Offloading in CloudsabstractSince Infrastructure-as-a-Service (IaaS) clouds contain many vulnerable virtual machines (VMs), intrusion detection systems (IDSes) should be run for all the VMs. IDS offloading is promising for this purpose because it allows IaaS providers to run IDSes in the outside of VMs without any cooperation of the users. However, offloaded IDSes cannot continue to monitor their target VM when the VM is migrated to another host. In this paper, we propose VMCoupler for enabling co-migration of offloaded IDSes and their target VM. Our approach is running offloaded IDSes in a special VM called a guard VM, which can monitor the internals of the target VM using VM introspection. VMCoupler can migrate a guard VM together with its target VM and restore the state of VM introspection at the destination. The migration processes of these two VMs are synchronized so that the target VM does not run without being monitored. We have confirmed that the overheads of kernel monitoring and co-migration were small. Kenichi Kourai, Hisato Utsunomiya |
CloudCom (1) | 1 |
| 2012 | Dependable and secure remote management in IaaS cloudsabstractIn Infrastructure-as-a-Service (IaaS) clouds, the users manage the systems in the provided virtual machines (VMs) called user VMs through remote management software such as Virtual Network Computing (VNC). For dependability, they often perform out-of-band remote management via the management VM. Even in the case of system failures inside their VMs, the users could directly access their systems. However, the management VM is not always trustworthy in IaaS. Once outside or inside attackers intrude into the management VM, they could easily eavesdrop on all the inputs and outputs in remote management. To solve this security issue, this paper proposes FBCrypt for preventing information leakage via the management VM in out-of-band remote management. FBCrypt encrypts the inputs and outputs between a VNC client and a user VM using the virtual machine monitor (VMM). Sensitive information is protected against the management VM between them. The VMM intercepts the reads of virtual devices by a user VM and decrypts the inputs, whereas it intercepts the updates of a framebuffer by a user VM and encrypts the pixel data. We have implemented FBCrypt in Xen and TightVNC and confirmed that any keystrokes or pixel data did not leak. Tomohisa Egawa, Naoki Nishimura, Kenichi Kourai |
CloudCom | 3 |
| 2012 | A Secure Framework for Monitoring Operating Systems Using SPEs in Cell/B.EabstractRecently, even operating systems are often compromised by the attackers. Since a compromised operating system affects all the applications including security software on top of it, the integrity of the operating system should be guaranteed. However, it is difficult to monitor the operating system securely. In this paper, we propose SPE Observer, which is a framework for securely monitoring operating systems using SPEs in Cell/B.E. SPE Observer guarantees the integrity and confidentiality of monitoring systems by the isolation mode of SPEs. To complement the isolation mode, SPE Observer monitors the running status of monitoring systems from an external security proxy. In addition, it schedules monitoring systems to mitigate the performance degradation of applications due to occupying SPEs. We have implemented SPE Observer in PlayStation 3 and developed the integrity monitor of the operating system. According to our experiments, it was shown that the integrity monitor on an SPE could detect a compromised operating system and that the application performance was dramatically improved by scheduling the integrity monitor. Kenichi Kourai, Takuya Nagata |
PRDC | 1 |
| 2011 | Fast and correct performance recovery of operating systems using a virtual machine monitorabstractRebooting an operating system is a final but effective recovery technique. However, the system performance largely degrades just after the reboot due to the page cache being lost in the main memory. For fast performance recovery, we propose a new reboot mechanism called the warm-cache reboot. The warm-cache reboot preserves the page cache during the reboot and enables an operating system to restore it after the reboot, with the help of a virtual machine monitor (VMM). To perform correct recovery, the VMM guarantees that the reused page cache is consistent with the corresponding files on disks. We have implemented the warm-cache reboot mechanism in the Xen VMM and the Linux operating system. Our experimental results showed that the warm-cache reboot decreased performance degradation just after the reboot. In addition, we confirmed that the file cache corrupted by faults was not reused. The overheads for maintaining cache consistency were not usually large. Kenichi Kourai |
VEE | 1 |
| 2011 | Fast Software Rejuvenation of Virtual Machine MonitorsabstractAs server consolidation using virtual machines (VMs) is carried out, software aging of virtual machine monitors (VMMs) is becoming critical. Since a VMM is fundamental software for running VMs, its performance degradation or crash failure affects all VMs running on top of it. To counteract such software aging, a proactive technique called software rejuvenation has been proposed. A simple example of rejuvenation is to reboot a VMM. However, simply rebooting a VMM is undesirable because that needs rebooting operating systems on all VMs. In this paper, we propose a new technique for fast rejuvenation of VMMs called the warm-VM reboot. The warm-VM reboot enables efficiently rebooting only a VMM by suspending and resuming VMs without saving the memory images to persistent storage. To achieve this, we have developed two mechanisms: on-memory suspend/resume of VMs and quick reload of a VMM. Compared with a normal reboot, the warm-VM reboot reduced the downtime by 74 percent at maximum. It also prevented the performance degradation due to cache misses after the reboot, which was 52 percent in case of a normal reboot. In a cluster environment, the warm-VM reboot achieved higher total throughput than the system using VM migration and a normal reboot. Kenichi Kourai, Shigeru Chiba |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2010 | A Secure System-Wide Process Scheduler across Virtual MachinesabstractServer consolidation using virtual machines (VMs) makes it difficult to execute processes as the administrators intend. A process scheduler in each VM is not aware of the other VM and schedules only processes in one VM independently. To solve this problem, process scheduling across VMs is necessary. However, such system-wide scheduling is vulnerable to denial-of-service (DoS) attacks from a compromised VM against the other VMs. In this paper, we propose the Monarch scheduler, which is a secure system-wide process scheduler running in the virtual machine monitor (VMM). The Monarch scheduler monitors the execution of processes and changes the scheduling behavior in all VMs. To change process scheduling from the VMM, it manipulates run queues and process states consistently without modifying guest operating systems. Its hybrid scheduling mitigates DoS attacks by leveraging performance isolation among VMs. We confirmed that the Monarch scheduler could achieve useful scheduling and the overheads were small. Hidekazu Tadokoro, Kenichi Kourai, Shigeru Chiba |
PRDC | 2 |
| 2009 | BitVisor: a thin hypervisor for enforcing i/o device securityabstractVirtual machine monitors (VMMs), including hypervisors, are a popular platform for implementing various security functionalities. However, traditional VMMs require numerous components for providing virtual hardware devices and for sharing and protecting system resources among virtual machines (VMs), enlarging the code size of and reducing the reliability of the VMMs.This paper introduces a hypervisor architecture, called parapass-through, designed to minimize the code size of hypervisors by allowing most of the I/O access from the guest operating system (OS) to pass-through the hypervisor, while the minimum access necessary to implement security functionalities is completely mediated by the hypervisor. This architecture uses device drivers of the guest OS to handle devices, thereby reducing the size of components in the hypervisor to provide virtual devices. This architecture also allows to run only single VM on it, eliminating the components for sharing and protecting system resources among VMs.We implemented a hypervisor called BitVisor and a parapass-through driver for enforcing storage encryption of ATA devices based on the parapass-through architecture. The experimental result reveals that the hypervisor and ATA driver require approximately 20 kilo lines of code (KLOC) and 1.4 KLOC respectively. Takahiro Shinagawa, Hideki Eiraku, Kouichi Tanimoto, Kazumasa Omote, Shoichi Hasegawa, Takashi Horie, Manabu Hirano, Kenichi Kourai, Yoshihiro Oyama, Eiji Kawai, Kenji Kono, Shigeru Chiba, Yasushi Shinjo, Kazuhiko Kato |
VEE | 8 |
| 2007 | A Fast Rejuvenation Technique for Server Consolidation with Virtual MachinesabstractAs server consolidation using virtual machines (VMs) is carried out, software aging of virtual machine monitors (VMMs) is becoming critical. Performance degradation or crash failure of a VMM affects all VMs on it. To counteract such software aging, a proactive technique called software rejuvenation has been proposed. A typical example of rejuvenation is to reboot a VMM. However, simply rebooting a VMM is undesirable because that needs rebooting operating systems on all VMs. In this paper, we propose a new technique for fast rejuvenation of VMMs called the warm-VM reboot. The warm-VM reboot enables efficiently rebooting only a VMM by suspending and resuming VMs without accessing the memory images. To achieve this, we have developed two mechanisms: on-memory suspend/resume of VMs and quick reload of VMMs. The warm- VM reboot reduces the downtime and prevents the performance degradation due to cache misses after the reboot. Kenichi Kourai, Shigeru Chiba |
DSN | 1 |
| 2006 | A dynamic aspect-oriented system for OS kernelsabstractWe propose a dynamic aspect-oriented system for operating system (OS) kernels written in the C language. Unlike other similar systems, our system named KLASY allows the users to pointcut not only function calls but also member accesses to structures. This feature helps the developers who want to use aspects for profiling or debugging an OS kernel. To enable this, KLASY uses a modified C compiler for compiling an OS kernel. The modified compiler produces extended symbol information, which enables a dynamic weaver to find the memory addresses of join point shadows during runtime. Since a normal C compiler produces only limited symbol information, other dynamic aspect-oriented systems for C have been able to pointcut only function calls. We have implemented KLASY for Linux with the GNU C compiler. Our experiments revealed that KLASY achieves sufficient execution performance for practical use. Our case studies disclosed that KLASY is useful for real applications. Yoshisato Yanagisawa, Kenichi Kourai, Shigeru Chiba |
GPCE | 2 |
| 2005 | HyperSpector: virtual distributed monitoring environments for secure intrusion detectionabstractIn this paper, a virtual distributed monitoring environment called HyperSpector is described that achieves secure intrusion detection in distributed computer systems. While multiple intrusion detection systems (IDSes) can protect a distributed system from attackers, they can increase the number of insecure points in the protected system. HyperSpector overcomes this problem without any additional hardware by using virtualization to isolate each IDS from the servers it monitors. The IDSes are located in a virtual machine called an IDS VM and the servers are located in a server VM. The IDS VMs among different hosts are connected using a virtual network. To enable legacy IDSes running in the IDS VM to monitor the server VM, HyperSpector provides three inter-VM monitoring mechanisms: software port mirroring, inter-VM disk mounting, and inter-VM process mapping. Consequently, active attacks, which directly attack the IDSes, are prevented. The impact of passive attacks, which wait until data including malicious code is read by an IDS and the IDS becomes compromised, is confined to within an affected HyperSpector environment. Kenichi Kourai, Shigeru Chiba |
VEE | 1 |
| 2003 | Secure and Manageable Virtual Private Networks for End-usersabstractThis paper presents personal networks, which integrate a VPN and the per-VPN execution environments of the hosts included in the VPN. The key point is that each execution environment called a portspace is bound to only one VPN, i.e., single-homed. Using this feature of portspaces, personal networks address several problems at multi-homed hosts that use multiple VPNs. Information flow is separated by personal networks so that it is not mixed at multi-homed hosts. IP addressing in a personal network is independent of the other personal networks, even the base network, and therefore does not conflict with those of other networks at multi-homed hosts. In addition, personal networks provide facilities for easy bootstrapping so that the end-users can construct such isolated networks easily. Inheritance of portspaces supports the creation of new portspaces based on existing portspaces. Self-construction of personal networks enables end-users to construct personal networks without help from the base network. Kenichi Kourai, Toshio Hirotsu, Koji Sato, Osamu Akashi, Kensuke Fukuda, Toshiharu Sugawara, Shigeru Chiba |
LCN | 1 |
| 2001 | A Secure Access Control Mechanism against Internet CrackersabstractInternet servers are always in danger of being "highjacked" by various attacks, like the buffer overflow attack. We propose a process cleaning technique for making an access control mechanism secure against hijacking. To minimize damage in cases where the full control of the servers is stolen, access restrictions must be imposed on the servers. However, designing a secure access control mechanism is not easy, because that mechanism itself can be a security hole. Process cleaning prevents malicious code injected by a cracker from illegally removing access restrictions from a hijacked server. In this paper, we describe the access control mechanism of our Compacto operating system using process cleaning. According to the results of our experiments, process cleaning can be implemented with acceptable performance overheads. Kenichi Kourai, Shigeru Chiba |
ICDCS | 1 |