00SEVen: Remote Inspection of TEE VMs using In-VM Agents
Published:
While the strong hardware-based isolation of TEE VMs (TVMs) protects sensitive client data against a compromised cloud platform, it also renders existing VM introspection (VMI) capabilities unfeasible. Therefore, customers lose the capability to securely monitor their TVMs for in-VM attacks or perform a post-mortem analysis. Out-of-VM accesses are blocked while in-VM agents are not isolated from attackers that have compromised the TVM. 00SEVen overcomes these challenges by enabling secure remote VMI for AMD-based TVMs using new hardware-protected, attestable in-VM agents.