From mboxrd@z Thu Jan 1 00:00:00 1970 From: Kai Luo Subject: Question's about to detect unauthorized memory access Date: Tue, 9 Jul 2013 03:52:55 -0700 (PDT) Message-ID: <2095964426.21089493.1373367175480.JavaMail.root@vmware.com> References: <1725921008.21075110.1373365505787.JavaMail.root@vmware.com> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============5872130501176531634==" Return-path: In-Reply-To: <1725921008.21075110.1373365505787.JavaMail.root@vmware.com> List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Sender: xen-devel-bounces@lists.xen.org Errors-To: xen-devel-bounces@lists.xen.org To: xen-devel@lists.xensource.com List-Id: xen-devel@lists.xenproject.org --===============5872130501176531634== Content-Type: multipart/alternative; boundary="----=_Part_21089492_822600595.1373367175479" ------=_Part_21089492_822600595.1373367175479 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Hi:=20 To detect and handle unauthorized memory map from hvm to dom0=EF=BC=8CI fou= nd xsm can prevent a privileged domain from arbitrarily mapping pages from = other domains,however,I try to find whether there is another way. So I try = to trap the memory access and compare the page owner whth the accessor, if = they are different, somthing must happend and a warning to the administrato= r will be raised.=20 My question is how can I trap the memory access? Is there any other mechani= sm to detect unauthorized memory map?With EPT/NPT, memory access are so clo= sed to hardware that I don=E2=80=98t know how should I trap it?Can you give= me any suggestion?=20 Thank you very much!=20 Jone=20 ------=_Part_21089492_822600595.1373367175479 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable
Hi:
    To d= etect and handle unauthorized memory map from hvm to dom0=EF=BC=8CI fo= und xsm can  prevent a privileged domain from arbitrarily mapping page= s from other domains,however,I try to find whether there is another way.&nb= sp;So I try to  trap the memory access and  compare the page owne= r whth the accessor, if they are different, somthing must happend and a war= ning to the administrator will be raised.
    My questi= on is how can I trap the memory access? Is there any other mechanism to det= ect unauthorized memory map?With EPT/NPT, memory access are so closed to ha= rdware that I don=E2=80=98t know how should I trap it?Can you give me any s= uggestion?
   &nb= sp;Thank you very much!
Jone

------=_Part_21089492_822600595.1373367175479-- --===============5872130501176531634== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Xen-devel mailing list Xen-devel@lists.xen.org http://lists.xen.org/xen-devel --===============5872130501176531634==--