User Tools

Site Tools


linux:apps:kvm:kvm-hardening

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
linux:apps:kvm:kvm-hardening [2026/09/13 15:03] – [Network containing] oscarlinux:apps:kvm:kvm-hardening [2026/09/16 16:31] (current) – [Network containing] oscar
Line 67: Line 67:
 ------------------------------------------------------- -------------------------------------------------------
  
-!/bin/bash+#!/bin/bash
  
 set -euo pipefail set -euo pipefail
  
-VM_NAME="Debian13-ESP32-ARMHF" +NFT="/usr/sbin/nft" 
-VM_MAC="52:54:00:7e:d3:ee" +VM_NAME="$1" 
 +VM_MAC=$(/usr/bin/virsh domiflist "$1" | awk '/:[0-9a-fA-F]/ {print $5}')
 LIBVIRT_BRIDGE="virbr0" LIBVIRT_BRIDGE="virbr0"
-ALLOWED_IPV4="192.168.178.1" +HOST_INTERFACE="enp2s0" 
- +BLOCKED_IPV4_RANGES="{ 192.168.0.0/16 }" 
-NFT="/usr/sbin/nft" +BLOCKED_IPV6_RANGES="{ 2001:1c00:2e07:fa0a::/64, fdaa:66:67::/48 }"
 TABLE="vm_filter" TABLE="vm_filter"
 CHAIN="vm_${VM_NAME//[^a-zA-Z0-9_]/_}" CHAIN="vm_${VM_NAME//[^a-zA-Z0-9_]/_}"
Line 86: Line 85:
     "$NFT" delete table inet "$TABLE" 2>/dev/null || true     "$NFT" delete table inet "$TABLE" 2>/dev/null || true
     "$NFT" add table inet "$TABLE"     "$NFT" add table inet "$TABLE"
-    "$NFT" add chain inet "$TABLE" "$CHAIN" \ +    "$NFT" add chain inet "$TABLE" "$CHAIN" '{ type filter hook forward priority -300; policy accept; }' 
-        '{ type filter hook forward priority -300; policy accept; }'+ 
 +    # Allow established and related return traffic 
 +    "$NFT" add rule inet "$TABLE" "$CHAIN" ct state established,related accept
  
     # Allow only VM -> 192.168.178.1     # Allow only VM -> 192.168.178.1
-    "$NFT" add rule inet "$TABLE" "$CHAIN" \ +     "$NFT" add rule inet "$TABLE" "$CHAIN" ether saddr "$VM_MAC" ip daddr "$BLOCKED_IPV4_RANGES" drop 
-        iifname "$LIBVIRT_BRIDGE" \ +     "$NFT" add rule inet "$TABLE" "$CHAIN" ether saddr "$VM_MAC" ip6 daddr "$BLOCKED_IPV6_RANGES" drop
-        ether saddr "$VM_MAC" \ +
-        ip daddr "$ALLOWED_IPV4" \ +
-        accept+
  
-    # Drop everything else originating from this VM. +    # ALLOW remaining traffic from the VM out to the internet via enp2s0 
-    # This includes IPv4 and IPv6. +    "$NFT" add rule inet "$TABLE" "$CHAIN" ether saddr "$VM_MAC" oifname "$HOST_INTERFACE" accept
-    "$NFT" add rule inet "$TABLE" "$CHAIN" \ +
-        iifname "$LIBVIRT_BRIDGE" \ +
-        ether saddr "$VM_MAC" \ +
-        drop+
 } }
 +
 remove_rules() remove_rules()
 { {
Line 137: Line 132:
 Check if the firewall settings are created and removed with: Check if the firewall settings are created and removed with:
   # nft list ruleset   # nft list ruleset
 +The firewall settings will look something like:
 +```
 +table inet vm_filter {
 + chain vm_Debian13_ESP {
 + type filter hook forward priority raw; policy accept;
 + ct state established,related accept
 + ether saddr 51:44:60:7e:d3:fe ip daddr 192.168.0.0/16 drop
 + ether saddr 51:44:60:7e:d3:fe ip6 daddr { 2001:1c00:2e07:fa0a::/64, fdaa:66:67::/48 } drop
 + ether saddr 51:44:60:7e:d3:fe oifname "enp2s0" accept
 + }
 +}
 +```
 +
 +## Kernel Samepage Merging (KSM)
 +In Linux, KSM (Kernel Samepage Merging) is a feature that scans your system's RAM looking for identical memory pages. When it finds matching pages, it merges them into a single, shared page using a mechanism called Copy-on-Write (CoW)
 +
 +  * The ksm service controls the actual raw kernel thread (ksmd) that does the heavy lifting.
 +  * The ksmtuned service is a user-space daemon. It actively watches your system and dynamically adjusts the tuning parameters of the kernel thread (like how fast it scans memory) based on how many QEMU/KVM instances are currently running.
 +
 +#### The Security Risk: Side-Channel Attacks
 +While KSM is great for saving RAM on high-density servers, it introduces a major security flaw called a Memory Side-Channel / Cache-Leak Attack. [1, 2] 
 +Because memory pages are shared between the host and the guest, a malicious process inside your Debian guest can perform precise timing measurements on memory access. By deliberately modifying a page and measuring how long it takes to process, the guest can figure out if that same data exists elsewhere in the host system's RAM. This can allow an attacker to bypass virtualization barriers and leak sensitive host data (like cryptographic keys or passwords). [2, 5] 
 +
 +Even if you only run a single Debian guest, KSM can still merge identical pages between your one guest and the Debian host operating system. If ksmtuned kicks in and starts aggressive page merging, the side-channel attack vector remains open between your isolated guest and your underlying hypervisor.
 +
 +#### Check if KSM is running
 +To check if ksmtuned and the underlying Kernel Samepage Merging (KSM) engine are active on your Debian Trixie host, run these diagnostic commands:
 +  systemctl status ksmtuned ksm
 +
 +What to look for: If it says Active: active (running), it is active. If it says Active: inactive (dead) or loaded (...; masked), it is successfully disabled.
 +
 +#### How to completely disable KSM
 +To ensure no memory deduplication happens at all, you should permanently stop and disable both the tuning daemon and the kernel driver: [5] 
 +
 +   1. Stop and mask the services so they can never be started by other system triggers:
 +   
 +   sudo systemctl disable --now ksm ksmtuned
 +   sudo systemctl mask ksm ksmtuned
 +   
 +   2. Force the kernel to instantly unshare any pages it has already merged:
 +   
 +   echo 2 | sudo tee /sys/kernel/mm/ksm/run
 +   
 +(Setting this to 2 completely disables the engine and forces the kernel to unmerge everything immediately. Setting it to 0 only stops it from scanning new pages). [2, 5] 
  
  
linux/apps/kvm/kvm-hardening.1789311838.txt.gz · Last modified: by oscar