RealmEye: Virtual Machine Introspection for Arm CCA Realm VMs

📅 2026-08-13
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the lack of a trustworthy virtual machine introspection (VMI) mechanism in Arm CCA Realm VMs, which leaves tenants unable to detect kernel-level attacks—such as rootkits—without trusting the hypervisor. The paper presents the first agentless, hardware-isolated VMI approach by placing the complete introspection logic within the Realm Management Monitor (RMM) operating at R-EL2. This design requires no modifications to the Realm guest or reliance on in-guest agents, enabling strongly isolated monitoring that remains invisible to external entities. Leveraging page-level access traps, VM pause-and-snapshot semantics, and hardware-backed attestation channels, the system integrates seamlessly with existing toolchains like LibVMI and DRAKVUF. Evaluated on the Arm FVP platform, it successfully detects Diamorphine rootkit techniques, including process hiding and syscall table hooking, with monitoring overhead scaling linearly with primitive invocation count, thereby demonstrating both efficacy and predictable performance.
📝 Abstract
Confidential VMs (CVMs) have become the dominant substrate for sensitive cloud workloads, from financial services to privacy-preserving AI inference. The hardware isolation that protects these CVMs from a malicious cloud also blinds their owners to what runs inside them: kernel rootkits planted via network or supply-chain attacks can hide processes, tamper with kernel data, and exfiltrate model weights under the cover of the same isolation that defends the VM. Tenants therefore need to inspect a running CVM from outside, yet classical VM introspection (VMI) presupposes a trusted Hypervisor, which CVMs exclude from the TCB. The state-of-the-art CVM-VMI system, 00SEVen, restores introspection on AMD SEV-SNP via an in-VM agent at a privileged tier (VMPL0), a mechanism that does not exist on Arm CCA, leaving Realm VMs without any introspection solution. We present RealmEye, the first VMI system for Arm CCA Realm VMs. RealmEye places the entire introspection logic inside the Realm Management Monitor (RMM) at R-EL2, achieving hardware-enforced separation between the monitor and the monitored VM: no agent runs inside the Realm, and the Realm remains unmodified. RealmEye reads Realm memory and registers, suspends the VM for consistent snapshots, and traps page-level accesses, without relying on any in-VM interface. A periodic, self-driven trigger mode keeps scan timing internal to the RMM, preventing the Hypervisor from colluding with in-Realm rootkits. Results are returned to the remote owner over a hardware-attested channel, and a CCA driver backend lets existing tools such as LibVMI and DRAKVUF interoperate with RealmEye unchanged. On the Arm FVP, RealmEye detects process hiding and syscall-table hooking by Diamorphine, and its in-RMM cost is linearly predictable from primitive invocation counts.
Problem

Research questions and friction points this paper is trying to address.

Confidential VMs
Virtual Machine Introspection
Arm CCA
Rootkit Detection
Hardware Isolation
Innovation

Methods, ideas, or system contributions that make the work stand out.

Virtual Machine Introspection
Arm CCA
Realm Management Monitor
Hardware-enforced Isolation
Confidential Computing
🔎 Similar Papers
No similar papers found.
R
Ruofei Qu
Institute of Software, Chinese Academy of Sciences, Beijing 100190, China
Wei Feng
Wei Feng
Professor,Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences.
Demand ResponseMicrogridBuilding Energy EfficiencyEnergy System Decarbonization
H
Hongzhan Ma
Institute of Software, Chinese Academy of Sciences, Beijing 100190, China
M
Menghan Jia
Institute of Software, Chinese Academy of Sciences, Beijing 100190, China
M
Muyan Shen
University of Chinese Academy of Sciences, Beijing 100049, China
Yu Qin
Yu Qin
Peking University
Additive ManufacturingBone Implant