Hypervisor-Enforced Kernel Integrity (Heki)(github.com) |
Hypervisor-Enforced Kernel Integrity (Heki)(github.com) |
Hypervisor-Enforced Kernel Integrity (Heki):
Heki is a proof-of-concept that implements new KVM features (extended page tracking, MBEC support, CR pinning) and defines a new API to protect guest VMs. It is designed to be merged with the mainline project. It is inspired from other private implementations currently in use (e.g. Windows's Virtual Secure Mode), but our approach is tailored to Linux specificities.