{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T01:12:09Z","timestamp":1780708329964,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":124,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,3,28]],"date-time":"2022-03-28T00:00:00Z","timestamp":1648425600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,3,28]]},"DOI":"10.1145\/3492321.3519589","type":"proceedings-article","created":{"date-parts":[[2022,3,28]],"date-time":"2022-03-28T14:28:18Z","timestamp":1648477698000},"page":"678-696","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["VMSH"],"prefix":"10.1145","author":[{"given":"J\u00f6rg","family":"Thalheim","sequence":"first","affiliation":[{"name":"Technical University of Munich"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Peter","family":"Okelmann","sequence":"additional","affiliation":[{"name":"Technical University of Munich"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Harshavardhan","family":"Unnibhavi","sequence":"additional","affiliation":[{"name":"Technical University of Munich"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Redha","family":"Gouicem","sequence":"additional","affiliation":[{"name":"Technical University of Munich"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pramod","family":"Bhatotia","sequence":"additional","affiliation":[{"name":"Technical University of Munich"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,3,28]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Advanced Micro Devices Inc. 2022. Homepage of AMD SEV. https:\/\/developer.amd.com\/sev\/.  Advanced Micro Devices Inc. 2022. Homepage of AMD SEV. https:\/\/developer.amd.com\/sev\/."},{"key":"e_1_3_2_1_2_1","volume-title":"17th USENIX Symposium on Networked Systems Design and Implementation (NSDI 20)","author":"Agache Alexandra","year":"2020","unstructured":"Alexandra Agache , Marc Brooker , Alexandra Iordache , Anthony Liguori , Rolf Neugebauer , Phil Piwonka , and Diana-Maria Popa . 2020 . Firecracker: Lightweight virtualization for serverless applications . In 17th USENIX Symposium on Networked Systems Design and Implementation (NSDI 20) . USENIX Association, Santa Clara, CA, 419--434. Alexandra Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori, Rolf Neugebauer, Phil Piwonka, and Diana-Maria Popa. 2020. Firecracker: Lightweight virtualization for serverless applications. In 17th USENIX Symposium on Networked Systems Design and Implementation (NSDI 20). USENIX Association, Santa Clara, CA, 419--434."},{"key":"e_1_3_2_1_3_1","unstructured":"Alpine maintainers. 2021. Alpine Linux security database. https:\/\/secdb.alpinelinux.org\/.  Alpine maintainers. 2021. Alpine Linux security database. https:\/\/secdb.alpinelinux.org\/."},{"key":"e_1_3_2_1_4_1","unstructured":"Amazon. 2021. Accessing Amazon CloudWatch logs for AWS Lambda. https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/monitoring-cloudwatchlogs.html.  Amazon. 2021. Accessing Amazon CloudWatch logs for AWS Lambda. https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/monitoring-cloudwatchlogs.html."},{"key":"e_1_3_2_1_5_1","unstructured":"Amazon. 2021. AWS X-Ray. https:\/\/aws.amazon.com\/xray\/.  Amazon. 2021. AWS X-Ray. https:\/\/aws.amazon.com\/xray\/."},{"key":"e_1_3_2_1_6_1","unstructured":"Amazon. 2021. Image scanning on Amazon ECR. https:\/\/docs.aws.amazon.com\/AmazonECR\/latest\/userguide\/image-scanning.html.  Amazon. 2021. Image scanning on Amazon ECR. https:\/\/docs.aws.amazon.com\/AmazonECR\/latest\/userguide\/image-scanning.html."},{"key":"e_1_3_2_1_7_1","unstructured":"Amazon. 2021. Working with AWS Lambda function metrics. https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/monitoring-metrics.html.  Amazon. 2021. Working with AWS Lambda function metrics. https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/monitoring-metrics.html."},{"key":"e_1_3_2_1_8_1","unstructured":"Amazon. 2021. Working with AWS Systems Manager (SSM) Agent. https:\/\/docs.aws.amazon.com\/systems-manager\/latest\/userguide\/ssm-agent.html.  Amazon. 2021. Working with AWS Systems Manager (SSM) Agent. https:\/\/docs.aws.amazon.com\/systems-manager\/latest\/userguide\/ssm-agent.html."},{"key":"e_1_3_2_1_9_1","unstructured":"Andreas Lundqvist. 2016. Linux distribution timeline. https:\/\/de.wikipedia.org\/wiki\/Datei:Linux_Distribution_Timeline.svg.  Andreas Lundqvist. 2016. Linux distribution timeline. https:\/\/de.wikipedia.org\/wiki\/Datei:Linux_Distribution_Timeline.svg."},{"key":"e_1_3_2_1_10_1","unstructured":"Ronnie Sahlberg Andrew Tridgell. 2021. Homepage of DBENCH. https:\/\/dbench.samba.org\/.  Ronnie Sahlberg Andrew Tridgell. 2021. Homepage of DBENCH. https:\/\/dbench.samba.org\/."},{"key":"e_1_3_2_1_11_1","unstructured":"Andy Honig and Nelly Porter. 2021. 7 ways we harden our KVM hypervisor at Google Cloud: security in plaintext. https:\/\/cloud.google.com\/blog\/products\/gcp\/7-ways-we-harden-our-kvm-hypervisor-at-google-cloud-security-in-plaintext.  Andy Honig and Nelly Porter. 2021. 7 ways we harden our KVM hypervisor at Google Cloud: security in plaintext. https:\/\/cloud.google.com\/blog\/products\/gcp\/7-ways-we-harden-our-kvm-hypervisor-at-google-cloud-security-in-plaintext."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2872362.2872371"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Ioana Baldini Paul Castro Kerry Chang Perry Cheng Stephen Fink Vatche Ishakian Nick Mitchell Vinod Muthusamy Rodric Rabbah Aleksander Slominski etal 2017. Serverless computing: Current trends and open problems. In Research advances in cloud computing. Springer Berlin Heidelberg Berlin Heidelberg 1--20.  Ioana Baldini Paul Castro Kerry Chang Perry Cheng Stephen Fink Vatche Ishakian Nick Mitchell Vinod Muthusamy Rodric Rabbah Aleksander Slominski et al. 2017. Serverless computing: Current trends and open problems. In Research advances in cloud computing. Springer Berlin Heidelberg Berlin Heidelberg 1--20.","DOI":"10.1007\/978-981-10-5026-8_1"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945462"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2465351.2465375"},{"key":"e_1_3_2_1_16_1","volume-title":"10th USENIX Symposium on Operating Systems Design and Implementation (OSDI 12)","author":"Belay Adam","year":"2012","unstructured":"Adam Belay , Andrea Bittau , Ali Mashtizadeh , David Terei , David Mazi\u00e8res , and Christos Kozyrakis . 2012 . Dune: Safe user-level access to privileged CPU features . In 10th USENIX Symposium on Operating Systems Design and Implementation (OSDI 12) . USENIX Association, Hollywood, CA, 335--348. Adam Belay, Andrea Bittau, Ali Mashtizadeh, David Terei, David Mazi\u00e8res, and Christos Kozyrakis. 2012. Dune: Safe user-level access to privileged CPU features. In 10th USENIX Symposium on Operating Systems Design and Implementation (OSDI 12). USENIX Association, Hollywood, CA, 335--348."},{"key":"e_1_3_2_1_17_1","volume-title":"9th USENIX Symposium on Operating Systems Design and Implementation (OSDI 10)","author":"Ben-Yehuda Muli","year":"2010","unstructured":"Muli Ben-Yehuda , Michael D Day , Zvi Dubitzky , Michael Factor , Nadav Har'El , Abel Gordon , Anthony Liguori , Orit Wasserman , and Ben-Ami Yassour . 2010 . The turtles project: Design and implementation of nested virtualization . In 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI 10) . Muli Ben-Yehuda, Michael D Day, Zvi Dubitzky, Michael Factor, Nadav Har'El, Abel Gordon, Anthony Liguori, Orit Wasserman, and Ben-Ami Yassour. 2010. The turtles project: Design and implementation of nested virtualization. In 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI 10)."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33338-5_2"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2002.1029005"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/HOTOS.2001.990073"},{"key":"e_1_3_2_1_21_1","unstructured":"Chris Mason &lt;chris.mason@oracle.com&gt;. 2021. Homepage of Compilebench. https:\/\/oss.oracle.com\/~mason\/compilebench\/.  Chris Mason &lt;chris.mason@oracle.com&gt;. 2021. Homepage of Compilebench. https:\/\/oss.oracle.com\/~mason\/compilebench\/."},{"key":"e_1_3_2_1_22_1","unstructured":"Cloud-hypervisor maintainers. 2021. Project page of cloud-hypervisor. https:\/\/github.com\/cloud-hypervisor\/cloud-hypervisor.  Cloud-hypervisor maintainers. 2021. Project page of cloud-hypervisor. https:\/\/github.com\/cloud-hypervisor\/cloud-hypervisor."},{"key":"e_1_3_2_1_23_1","unstructured":"Cloud Native computing foundation. 2021. Containerd - An industry-standard container runtime with an emphasis on simplicity robustness and portability. https:\/\/containerd.io\/.  Cloud Native computing foundation. 2021. Containerd - An industry-standard container runtime with an emphasis on simplicity robustness and portability. https:\/\/containerd.io\/."},{"key":"e_1_3_2_1_24_1","unstructured":"SQLite Consortium. 2021. Homepage of SQLite. http:\/\/sqlite.org\/.  SQLite Consortium. 2021. Homepage of SQLite. http:\/\/sqlite.org\/."},{"key":"e_1_3_2_1_26_1","unstructured":"Digitalocean. 2021. How to Regain Access to Droplets using the Recovery Console. https:\/\/docs.digitalocean.com\/products\/droplets\/resources\/recovery-console\/.  Digitalocean. 2021. How to Regain Access to Droplets using the Recovery Console. https:\/\/docs.digitalocean.com\/products\/droplets\/resources\/recovery-console\/."},{"key":"e_1_3_2_1_27_1","unstructured":"DMTF. 2022. Specifications of the Redfish standard. https:\/\/www.dmtf.org\/standards\/redfish.  DMTF. 2022. Specifications of the Redfish standard. https:\/\/www.dmtf.org\/standards\/redfish."},{"key":"e_1_3_2_1_28_1","unstructured":"Docker. 2021. Explore official Docker images. https:\/\/hub.docker.com\/search?q=&type=image&image_filter=official.  Docker. 2021. Explore official Docker images. https:\/\/hub.docker.com\/search?q=&type=image&image_filter=official."},{"key":"e_1_3_2_1_29_1","unstructured":"Docker. 2022. Docker homepage. https:\/\/www.docker.com\/.  Docker. 2022. Docker homepage. https:\/\/www.docker.com\/."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.11"},{"key":"e_1_3_2_1_31_1","unstructured":"Firecracker contributors. 2021. firecracker-containerd. https:\/\/github.com\/firecracker-microvm\/firecracker-containerd.  Firecracker contributors. 2021. firecracker-containerd. https:\/\/github.com\/firecracker-microvm\/firecracker-containerd."},{"key":"e_1_3_2_1_32_1","unstructured":"Firecracker contributors. 2021. Firecracker kernel configuration. https:\/\/github.com\/firecracker-microvm\/firecracker\/blob\/main\/resources\/microvm-kernel-x86_64.config.  Firecracker contributors. 2021. Firecracker kernel configuration. https:\/\/github.com\/firecracker-microvm\/firecracker\/blob\/main\/resources\/microvm-kernel-x86_64.config."},{"key":"e_1_3_2_1_33_1","volume-title":"4th USENIX Symposium on Networked Systems Design & Implementation (NSDI 07)","author":"Fonseca Rodrigo","year":"2007","unstructured":"Rodrigo Fonseca , George Porter , Randy H Katz , and Scott Shenker . 2007 . X-trace: A pervasive network tracing framework . In 4th USENIX Symposium on Networked Systems Design & Implementation (NSDI 07) . USENIX Association, USA, 20. Rodrigo Fonseca, George Porter, Randy H Katz, and Scott Shenker. 2007. X-trace: A pervasive network tracing framework. In 4th USENIX Symposium on Networked Systems Design & Implementation (NSDI 07). USENIX Association, USA, 20."},{"key":"e_1_3_2_1_34_1","volume-title":"Openstack: Open source cloud computing infrastructure. https:\/\/www.openstack.org\/.","author":"Foundation Openstack","year":"2021","unstructured":"Openstack Foundation . 2021 . Openstack: Open source cloud computing infrastructure. https:\/\/www.openstack.org\/. Openstack Foundation. 2021. Openstack: Open source cloud computing infrastructure. https:\/\/www.openstack.org\/."},{"key":"e_1_3_2_1_35_1","unstructured":"FreeBSD maintainers. 2021. ksyms - kernel symbol table interface. https:\/\/www.freebsd.org\/cgi\/man.cgi?query=ksyms&sektion=4&manpath=FreeBSD+8.0-RELEASE.  FreeBSD maintainers. 2021. ksyms - kernel symbol table interface. https:\/\/www.freebsd.org\/cgi\/man.cgi?query=ksyms&sektion=4&manpath=FreeBSD+8.0-RELEASE."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2517326.2451534"},{"key":"e_1_3_2_1_37_1","volume-title":"HYPERSHELL: A Practical Hypervisor Layer Guest OS Shell for Automated In-VM Management. In USENIX Annual Technical Conference (USENIX ATC). USENIX","author":"Fu Yangchun","year":"2014","unstructured":"Yangchun Fu , Junyuan Zeng , and Zhiqiang Lin . 2014 . HYPERSHELL: A Practical Hypervisor Layer Guest OS Shell for Automated In-VM Management. In USENIX Annual Technical Conference (USENIX ATC). USENIX , Philadelphia, PA, 85--96. Yangchun Fu, Junyuan Zeng, and Zhiqiang Lin. 2014. HYPERSHELL: A Practical Hypervisor Layer Guest OS Shell for Automated In-VM Management. In USENIX Annual Technical Conference (USENIX ATC). USENIX, Philadelphia, PA, 85--96."},{"key":"e_1_3_2_1_38_1","volume-title":"Ndss","volume":"3","author":"Garfinkel Tal","year":"2003","unstructured":"Tal Garfinkel , Mendel Rosenblum , 2003 . A virtual machine introspection based architecture for intrusion detection .. In Ndss , Vol. 3 . Citeseer, San Diego, California, USA, 191--206. Tal Garfinkel, Mendel Rosenblum, et al. 2003. A virtual machine introspection based architecture for intrusion detection.. In Ndss, Vol. 3. Citeseer, San Diego, California, USA, 191--206."},{"key":"e_1_3_2_1_39_1","unstructured":"Google. 2021. Container analysis and vulnerability scanning. https:\/\/cloud.google.com\/container-registry\/docs\/container-analysis.  Google. 2021. Container analysis and vulnerability scanning. https:\/\/cloud.google.com\/container-registry\/docs\/container-analysis."},{"key":"e_1_3_2_1_40_1","unstructured":"Google. 2021. Google OS Config Agent. https:\/\/github.com\/GoogleCloudPlatform\/osconfig.  Google. 2021. Google OS Config Agent. https:\/\/github.com\/GoogleCloudPlatform\/osconfig."},{"key":"e_1_3_2_1_41_1","unstructured":"Google. 2021. Guest Agent for Google Compute Engine. https:\/\/github.com\/GoogleCloudPlatform\/guest-agent.  Google. 2021. Guest Agent for Google Compute Engine. https:\/\/github.com\/GoogleCloudPlatform\/guest-agent."},{"key":"e_1_3_2_1_42_1","unstructured":"Google. 2021. Homepage of crosvm. https:\/\/chromium.googlesource.com\/chromiumos\/platform\/crosvm\/.  Google. 2021. Homepage of crosvm. https:\/\/chromium.googlesource.com\/chromiumos\/platform\/crosvm\/."},{"key":"e_1_3_2_1_43_1","unstructured":"Google. 2021. Installing the guest environment. https:\/\/cloud.google.com\/compute\/docs\/images\/install-guest-environment.  Google. 2021. Installing the guest environment. https:\/\/cloud.google.com\/compute\/docs\/images\/install-guest-environment."},{"key":"e_1_3_2_1_44_1","unstructured":"Google. 2021. Nested virtualization overview. https:\/\/cloud.google.com\/compute\/docs\/instances\/nested-virtualization\/overview.  Google. 2021. Nested virtualization overview. https:\/\/cloud.google.com\/compute\/docs\/instances\/nested-virtualization\/overview."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/SRDS.2011.26"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2893177"},{"key":"e_1_3_2_1_47_1","unstructured":"Hetzner AG. 2021. Hetzner Rescue System. https:\/\/docs.hetzner.com\/robot\/dedicated-server\/troubleshooting\/hetzner-rescue-system\/.  Hetzner AG. 2021. Hetzner Rescue System. https:\/\/docs.hetzner.com\/robot\/dedicated-server\/troubleshooting\/hetzner-rescue-system\/."},{"key":"e_1_3_2_1_48_1","volume-title":"SemperOS: A Distributed Capability System. In 2019 USENIX Annual Technical Conference (USENIX ATC 19)","author":"Hille Matthias","year":"2019","unstructured":"Matthias Hille , Nils Asmussen , Pramod Bhatotia , and Hermann H\u00e4rtig . 2019 . SemperOS: A Distributed Capability System. In 2019 USENIX Annual Technical Conference (USENIX ATC 19) . USENIX Association, Renton, WA, 709--722. https:\/\/www.usenix.org\/conference\/atc19\/presentation\/hille Matthias Hille, Nils Asmussen, Pramod Bhatotia, and Hermann H\u00e4rtig. 2019. SemperOS: A Distributed Capability System. In 2019 USENIX Annual Technical Conference (USENIX ATC 19). USENIX Association, Renton, WA, 709--722. https:\/\/www.usenix.org\/conference\/atc19\/presentation\/hille"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3409963.3410487"},{"key":"e_1_3_2_1_50_1","unstructured":"IBM. 2021. Getting started with KVM. https:\/\/www.ibm.com\/docs\/en\/cic\/1.1.3?topic=SSLL2F_1.1.3\/com.ibm.cloudin.doc\/overview\/Getting_started_tutorial.html.  IBM. 2021. Getting started with KVM. https:\/\/www.ibm.com\/docs\/en\/cic\/1.1.3?topic=SSLL2F_1.1.3\/com.ibm.cloudin.doc\/overview\/Getting_started_tutorial.html."},{"key":"e_1_3_2_1_51_1","unstructured":"IBM. 2021. IBM's Vulnerability Advisor. https:\/\/www.ibm.com\/docs\/en\/cloud-private\/3.2.0?topic=guide-vulnerability-advisor.  IBM. 2021. IBM's Vulnerability Advisor. https:\/\/www.ibm.com\/docs\/en\/cloud-private\/3.2.0?topic=guide-vulnerability-advisor."},{"key":"e_1_3_2_1_52_1","unstructured":"Intel. 2013. Intelligent Platform Management Interface Specification v2.0 rev. 1.1. https:\/\/www.intel.de\/content\/www\/de\/de\/products\/docs\/servers\/ipmi\/ipmi-second-gen-interface-spec-v2-rev1-1.html.  Intel. 2013. Intelligent Platform Management Interface Specification v2.0 rev. 1.1. https:\/\/www.intel.de\/content\/www\/de\/de\/products\/docs\/servers\/ipmi\/ipmi-second-gen-interface-spec-v2-rev1-1.html."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978321"},{"key":"e_1_3_2_1_54_1","unstructured":"Jens Axboe. 2021. Flexible I\/O Tester. https:\/\/github.com\/axboe\/fio.  Jens Axboe. 2021. Flexible I\/O Tester. https:\/\/github.com\/axboe\/fio."},{"key":"e_1_3_2_1_55_1","unstructured":"J\u00f6rg Thalheim. 2021. Runq fork with our modifications. https:\/\/github.com\/Mic92\/runq\/commits\/vmsh.  J\u00f6rg Thalheim. 2021. Runq fork with our modifications. https:\/\/github.com\/Mic92\/runq\/commits\/vmsh."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132749"},{"key":"e_1_3_2_1_57_1","unstructured":"Kata maintainers. 2021. Kata container kernel configuration. https:\/\/github.com\/kata-containers\/kata-containers\/blob\/main\/tools\/packaging\/kernel\/configs\/x86_64_kata_kvm_4.14.x.  Kata maintainers. 2021. Kata container kernel configuration. https:\/\/github.com\/kata-containers\/kata-containers\/blob\/main\/tools\/packaging\/kernel\/configs\/x86_64_kata_kvm_4.14.x."},{"key":"e_1_3_2_1_59_1","unstructured":"Linux kernel documentation. 2021. Seccomp BPF (SECure COMPuting with filters). https:\/\/www.kernel.org\/doc\/html\/latest\/userspace-api\/seccomp_filter.html.  Linux kernel documentation. 2021. Seccomp BPF (SECure COMPuting with filters). https:\/\/www.kernel.org\/doc\/html\/latest\/userspace-api\/seccomp_filter.html."},{"key":"e_1_3_2_1_60_1","unstructured":"Kernel maintainers. 2021. What is xfstests? https:\/\/kernel.googlesource.com\/pub\/scm\/fs\/ext2\/xfstests-bld\/+\/HEAD\/Documentation\/what-is-xfstests.md.  Kernel maintainers. 2021. What is xfstests? https:\/\/kernel.googlesource.com\/pub\/scm\/fs\/ext2\/xfstests-bld\/+\/HEAD\/Documentation\/what-is-xfstests.md."},{"key":"e_1_3_2_1_61_1","unstructured":"Kernel maintainers. 2021. xfstests-dev. https:\/\/git.kernel.org\/pub\/scm\/fs\/xfs\/xfstests-dev.git\/.  Kernel maintainers. 2021. xfstests-dev. https:\/\/git.kernel.org\/pub\/scm\/fs\/xfs\/xfstests-dev.git\/."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/1629575.1629596"},{"key":"e_1_3_2_1_63_1","unstructured":"Kubernetes. 2021. Ephemeral Containers. https:\/\/kubernetes.io\/docs\/concepts\/workloads\/pods\/ephemeral-containers\/.  Kubernetes. 2021. Ephemeral Containers. https:\/\/kubernetes.io\/docs\/concepts\/workloads\/pods\/ephemeral-containers\/."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447786.3456248"},{"key":"e_1_3_2_1_65_1","unstructured":"Michael Larabel. 2021. Homepage of Phoronix test suite. https:\/\/www.phoronix-test-suite.com\/.  Michael Larabel. 2021. Homepage of Phoronix test suite. https:\/\/www.phoronix-test-suite.com\/."},{"key":"e_1_3_2_1_66_1","unstructured":"Michael Larabel. 2021. Wiki page for the Phoronix disk test suite. https:\/\/openbenchmarking.org\/suite\/pts\/disk.  Michael Larabel. 2021. Wiki page for the Phoronix disk test suite. https:\/\/openbenchmarking.org\/suite\/pts\/disk."},{"key":"e_1_3_2_1_67_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Li Shih-Wei","year":"2019","unstructured":"Shih-Wei Li , John S. Koh , and Jason Nieh . 2019 . Protecting Cloud Virtual Machines from Hypervisor and Host Operating System Exploits . In 28th USENIX Security Symposium (USENIX Security 19) . USENIX Association, Santa Clara, CA, USA, 1357--1374. Shih-Wei Li, John S. Koh, and Jason Nieh. 2019. Protecting Cloud Virtual Machines from Hypervisor and Host Operating System Exploits. In 28th USENIX Security Symposium (USENIX Security 19). USENIX Association, Santa Clara, CA, USA, 1357--1374."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00049"},{"key":"e_1_3_2_1_69_1","volume-title":"12th USENIX Symposium on Networked Systems Design and Implementation (NSDI 15)","author":"Madhavapeddy Anil","year":"2015","unstructured":"Anil Madhavapeddy , Thomas Leonard , Magnus Skjegstad , Thomas Gazagnaire , David Sheets , Dave Scott , Richard Mortier , Amir Chaudhry , Balraj Singh , Jon Ludlam , 2015 . Jitsu: Just-in-time summoning of unikernels . In 12th USENIX Symposium on Networked Systems Design and Implementation (NSDI 15) . USENIX Association, USA, 559--573. Anil Madhavapeddy, Thomas Leonard, Magnus Skjegstad, Thomas Gazagnaire, David Sheets, Dave Scott, Richard Mortier, Amir Chaudhry, Balraj Singh, Jon Ludlam, et al. 2015. Jitsu: Just-in-time summoning of unikernels. In 12th USENIX Symposium on Networked Systems Design and Implementation (NSDI 15). USENIX Association, USA, 559--573."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/2490301.2451167"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/2541883.2541895"},{"key":"e_1_3_2_1_72_1","unstructured":"Kernel maintainers. 2021. Kernel Virtual Machine (KVM). https:\/\/www.linux-kvm.org\/page\/Main_Page.  Kernel maintainers. 2021. Kernel Virtual Machine (KVM). https:\/\/www.linux-kvm.org\/page\/Main_Page."},{"key":"e_1_3_2_1_73_1","unstructured":"Linux maintainers. 2021. pts(4) Linux Programmer's Manual. Linux foundation.  Linux maintainers. 2021. pts(4) Linux Programmer's Manual. Linux foundation."},{"key":"e_1_3_2_1_74_1","unstructured":"Libvirt maintainers. 2021. Virsh management user interface - domstats. https:\/\/www.libvirt.org\/manpages\/virsh.html#domstats.  Libvirt maintainers. 2021. Virsh management user interface - domstats. https:\/\/www.libvirt.org\/manpages\/virsh.html#domstats."},{"key":"e_1_3_2_1_75_1","unstructured":"OpenBSD maintainers. 2021. OpenSSH remote login client. OpenBSD.  OpenBSD maintainers. 2021. OpenSSH remote login client. OpenBSD."},{"key":"e_1_3_2_1_76_1","unstructured":"Overlayfs maintainers. 2021. Overlayfs FUSE implementation. CNCF.  Overlayfs maintainers. 2021. Overlayfs FUSE implementation. CNCF."},{"key":"e_1_3_2_1_77_1","unstructured":"QEMU maintainers. 2021. QEMU-GA(8) QEMU Guest Agent manual. QEMU.  QEMU maintainers. 2021. QEMU-GA(8) QEMU Guest Agent manual. QEMU."},{"key":"e_1_3_2_1_78_1","unstructured":"QEMU maintainers. 2021. Vhost-user protocol. https:\/\/qemu.readthedocs.io\/en\/latest\/interop\/vhost-user.html.  QEMU maintainers. 2021. Vhost-user protocol. https:\/\/qemu.readthedocs.io\/en\/latest\/interop\/vhost-user.html."},{"key":"e_1_3_2_1_79_1","volume-title":"Systemd-sysext: Activates System Extention Images. https:\/\/www.freedesktop.org\/software\/systemd\/man\/systemd-sysext.html.","author":"Systemd","year":"2021","unstructured":"Systemd maintainers. 2021 . Systemd-sysext: Activates System Extention Images. https:\/\/www.freedesktop.org\/software\/systemd\/man\/systemd-sysext.html. Systemd maintainers. 2021. Systemd-sysext: Activates System Extention Images. https:\/\/www.freedesktop.org\/software\/systemd\/man\/systemd-sysext.html."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132763"},{"key":"e_1_3_2_1_81_1","unstructured":"Microsoft. 2021. CVE-2021-38647: Open Management Infrastructure Remote Code Execution Vulnerability. https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-38647.  Microsoft. 2021. CVE-2021-38647: Open Management Infrastructure Remote Code Execution Vulnerability. https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-38647."},{"key":"e_1_3_2_1_82_1","unstructured":"Microsoft. 2021. Open Management Infrastructure (OMI). https:\/\/github.com\/microsoft\/omi.  Microsoft. 2021. Open Management Infrastructure (OMI). https:\/\/github.com\/microsoft\/omi."},{"key":"e_1_3_2_1_84_1","unstructured":"Maintainers of nix. 2022. Homepage of nix . https:\/\/nixos.org\/download.html.  Maintainers of nix. 2022. Homepage of nix . https:\/\/nixos.org\/download.html."},{"key":"e_1_3_2_1_85_1","unstructured":"The Regents of the University of California. 2021. Homepage of IOR. https:\/\/ior.readthedocs.io\/en\/latest\/.  The Regents of the University of California. 2021. Homepage of IOR. https:\/\/ior.readthedocs.io\/en\/latest\/."},{"key":"e_1_3_2_1_86_1","unstructured":"Peter Okelmann and J\u00f6rg Thalheim. 2021. lambda-pirate. https:\/\/github.com\/pogobanane\/lambda-pirate.  Peter Okelmann and J\u00f6rg Thalheim. 2021. lambda-pirate. https:\/\/github.com\/pogobanane\/lambda-pirate."},{"key":"e_1_3_2_1_87_1","unstructured":"Oracle. 2021. Oracle Virtualization. https:\/\/www.oracle.com\/virtualization\/.  Oracle. 2021. Oracle Virtualization. https:\/\/www.oracle.com\/virtualization\/."},{"key":"e_1_3_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.24"},{"key":"e_1_3_2_1_89_1","unstructured":"Peter Morjan. 2021. Runq - a hypervisor-based Docker runtime. https:\/\/github.com\/gotoz\/runq.  Peter Morjan. 2021. Runq - a hypervisor-based Docker runtime. https:\/\/github.com\/gotoz\/runq."},{"key":"e_1_3_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1145\/1655148.1655150"},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.3758\/s13414-013-0605-z"},{"key":"e_1_3_2_1_92_1","unstructured":"Project Zero. 2021. An EPYC escape: Case-study of a KVM breakout. https:\/\/googleprojectzero.blogspot.com\/2021\/06\/an-epycescape-case-study-of-kvm.html.  Project Zero. 2021. An EPYC escape: Case-study of a KVM breakout. https:\/\/googleprojectzero.blogspot.com\/2021\/06\/an-epycescape-case-study-of-kvm.html."},{"key":"e_1_3_2_1_93_1","unstructured":"Qemu maintainers. 2021. Homepage of qemu. https:\/\/www.qemu.org\/.  Qemu maintainers. 2021. Homepage of qemu. https:\/\/www.qemu.org\/."},{"key":"e_1_3_2_1_94_1","unstructured":"Qemu maintainers. 2021. QEMU - 'microvm' virtual platform (microvm). https:\/\/qemu.readthedocs.io\/en\/latest\/system\/i386\/microvm.html.  Qemu maintainers. 2021. QEMU - 'microvm' virtual platform (microvm). https:\/\/qemu.readthedocs.io\/en\/latest\/system\/i386\/microvm.html."},{"key":"e_1_3_2_1_95_1","unstructured":"Qemu maintainers. 2021. QEMU version 4.2.0 released. https:\/\/www.qemu.org\/2019\/12\/13\/qemu-4-2-0\/.  Qemu maintainers. 2021. QEMU version 4.2.0 released. https:\/\/www.qemu.org\/2019\/12\/13\/qemu-4-2-0\/."},{"key":"e_1_3_2_1_96_1","unstructured":"Qemu wiki authors. 2021. Documentation 9psetup. https:\/\/wiki.qemu.org\/Documentation\/9psetup.  Qemu wiki authors. 2021. Documentation 9psetup. https:\/\/wiki.qemu.org\/Documentation\/9psetup."},{"key":"e_1_3_2_1_97_1","volume-title":"Proceedings Linux Symposium 15","author":"Qumranet Avi","year":"2007","unstructured":"Avi Qumranet , Yaniv Qumranet , Dor Qumranet , Uri Qumranet , and Anthony Liguori . 2007 . KVM: The Linux virtual machine monitor . Proceedings Linux Symposium 15 (2007). Avi Qumranet, Yaniv Qumranet, Dor Qumranet, Uri Qumranet, and Anthony Liguori. 2007. KVM: The Linux virtual machine monitor. Proceedings Linux Symposium 15 (2007)."},{"key":"e_1_3_2_1_98_1","unstructured":"Red Hat Customer Portal. 2021. CVE-2015-3456. https:\/\/access.redhat.com\/security\/cve\/CVE-2015-3456.  Red Hat Customer Portal. 2021. CVE-2015-3456. https:\/\/access.redhat.com\/security\/cve\/CVE-2015-3456."},{"key":"e_1_3_2_1_99_1","doi-asserted-by":"publisher","DOI":"10.1145\/1400097.1400108"},{"key":"e_1_3_2_1_101_1","volume-title":"12th USENIX Symposium on Operating Systems Design and Implementation (SDI 16)","author":"Schatzberg Dan","year":"2016","unstructured":"Dan Schatzberg , James Cadden , Han Dong , Orran Krieger , and Jonathan Appavoo . 2016 . Ebbrt: A framework for building per-application library operating systems . In 12th USENIX Symposium on Operating Systems Design and Implementation (SDI 16) . USENIX Association, USA, 671--688. Dan Schatzberg, James Cadden, Han Dong, Orran Krieger, and Jonathan Appavoo. 2016. Ebbrt: A framework for building per-application library operating systems. In 12th USENIX Symposium on Operating Systems Design and Implementation (SDI 16). USENIX Association, USA, 671--688."},{"key":"e_1_3_2_1_102_1","unstructured":"shadow-utils maintainer. 2021. chpasswd(8) shadow-utils manual. Shadow maintainers.  shadow-utils maintainer. 2021. chpasswd(8) shadow-utils manual. Shadow maintainers."},{"key":"e_1_3_2_1_103_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653720"},{"key":"e_1_3_2_1_104_1","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304016"},{"key":"e_1_3_2_1_105_1","volume-title":"Mike Burrows, Pat Stephenson, Manoj Plakal, Donald Beaver, Saul Jaspan, and Chandan Shanbhag.","author":"Sigelman Benjamin H.","year":"2010","unstructured":"Benjamin H. Sigelman , Luiz Andr\u00e9 Barroso , Mike Burrows, Pat Stephenson, Manoj Plakal, Donald Beaver, Saul Jaspan, and Chandan Shanbhag. 2010 . Dapper, a Large-Scale Distributed Systems Tracing Infrastructure. Technical Report. Google, Inc . Benjamin H. Sigelman, Luiz Andr\u00e9 Barroso, Mike Burrows, Pat Stephenson, Manoj Plakal, Donald Beaver, Saul Jaspan, and Chandan Shanbhag. 2010. Dapper, a Large-Scale Distributed Systems Tracing Infrastructure. Technical Report. Google, Inc."},{"key":"e_1_3_2_1_106_1","unstructured":"Simon Sharwood. 2021. AWS adopts home-brewed KVM as new hypervisor. https:\/\/www.theregister.com\/2017\/11\/07\/aws_writes_new_kvm_based_hypervisor_to_make_its_cloud_go_faster\/.  Simon Sharwood. 2021. AWS adopts home-brewed KVM as new hypervisor. https:\/\/www.theregister.com\/2017\/11\/07\/aws_writes_new_kvm_based_hypervisor_to_make_its_cloud_go_faster\/."},{"key":"e_1_3_2_1_107_1","unstructured":"Stefan Hajnoczi. 2020. Proposal for MMIO\/PIO dispatch file descriptors. https:\/\/www.spinics.net\/lists\/kvm\/msg208139.html.  Stefan Hajnoczi. 2020. Proposal for MMIO\/PIO dispatch file descriptors. https:\/\/www.spinics.net\/lists\/kvm\/msg208139.html."},{"key":"e_1_3_2_1_108_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098583.3098586"},{"key":"e_1_3_2_1_109_1","unstructured":"J\u00f6rg Thalheim. 2022. Maintained fork of Linux for Ioregionfd patch. https:\/\/github.com\/Mic92\/linux\/tree\/ioregion-5.14.  J\u00f6rg Thalheim. 2022. Maintained fork of Linux for Ioregionfd patch. https:\/\/github.com\/Mic92\/linux\/tree\/ioregion-5.14."},{"key":"e_1_3_2_1_110_1","doi-asserted-by":"crossref","unstructured":"J\u00f6rg Thalheim. 2022. Run the evaluation. https:\/\/github.com\/Mic92\/vmsh\/blob\/main\/EVALUATION.md.  J\u00f6rg Thalheim. 2022. Run the evaluation. https:\/\/github.com\/Mic92\/vmsh\/blob\/main\/EVALUATION.md.","DOI":"10.1145\/3492321.3519589"},{"key":"e_1_3_2_1_111_1","volume-title":"Cntr: Lightweight OS Containers. In 2018 USENIX Annual Technical Conference (USENIX ATC 18)","author":"Thalheim J\u00f6rg","year":"2018","unstructured":"J\u00f6rg Thalheim , Pramod Bhatotia , Pedro Fonseca , and Baris Kasikci . 2018 . Cntr: Lightweight OS Containers. In 2018 USENIX Annual Technical Conference (USENIX ATC 18) . USENIX Association, Boston, MA, 199--212. J\u00f6rg Thalheim, Pramod Bhatotia, Pedro Fonseca, and Baris Kasikci. 2018. Cntr: Lightweight OS Containers. In 2018 USENIX Annual Technical Conference (USENIX ATC 18). USENIX Association, Boston, MA, 199--212."},{"key":"e_1_3_2_1_112_1","doi-asserted-by":"crossref","unstructured":"J\u00f6rg Thalheim and Peter Okelmann. 2022. Project page of vmsh. https:\/\/github.com\/Mic92\/vmsh.  J\u00f6rg Thalheim and Peter Okelmann. 2022. Project page of vmsh. https:\/\/github.com\/Mic92\/vmsh.","DOI":"10.1145\/3492321.3519589"},{"key":"e_1_3_2_1_113_1","doi-asserted-by":"publisher","DOI":"10.5281\/zenodo.6337102"},{"key":"e_1_3_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1145\/3135974.3135977"},{"key":"e_1_3_2_1_115_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447786.3456255"},{"key":"e_1_3_2_1_116_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319647.3325835"},{"key":"e_1_3_2_1_117_1","doi-asserted-by":"publisher","DOI":"10.1145\/2592798.2592812"},{"key":"e_1_3_2_1_118_1","volume-title":"Tsirkin and Cornelia Huck","author":"Michael","year":"2019","unstructured":"Michael S. Tsirkin and Cornelia Huck . 11 April 2019 . Virtual I\/O Device (VIRTIO) Version 1.1. OASIS Committee Specification 01 1.1 (11 April 2019), 1. Latest version: https:\/\/docs.oasis-open.org\/virtio\/virtio\/v1.1\/cs01\/virtio-v1.1-cs01.html. Michael S. Tsirkin and Cornelia Huck. 11 April 2019. Virtual I\/O Device (VIRTIO) Version 1.1. OASIS Committee Specification 01 1.1 (11 April 2019), 1. Latest version: https:\/\/docs.oasis-open.org\/virtio\/virtio\/v1.1\/cs01\/virtio-v1.1-cs01.html."},{"key":"e_1_3_2_1_119_1","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446714"},{"key":"e_1_3_2_1_120_1","unstructured":"Arjan van de Ven. 2015. An introduction to Clear Containers. https:\/\/lwn.net\/Articles\/644675\/.  Arjan van de Ven. 2015. An introduction to Clear Containers. https:\/\/lwn.net\/Articles\/644675\/."},{"key":"e_1_3_2_1_121_1","unstructured":"Rust vmm maintainers. 2021. rust-vmm . https:\/\/github.com\/rust-vmm.  Rust vmm maintainers. 2021. rust-vmm . https:\/\/github.com\/rust-vmm."},{"key":"e_1_3_2_1_122_1","unstructured":"Rust vmm maintainers. 2021. vmm-reference. https:\/\/github.com\/rust-vmm\/vmm-reference.  Rust vmm maintainers. 2021. vmm-reference. https:\/\/github.com\/rust-vmm\/vmm-reference."},{"key":"e_1_3_2_1_123_1","unstructured":"VMware. 2021. VMware ESXi: The Purpose-Built Bare Metal Hyper-visor. https:\/\/www.vmware.com\/products\/esxi-and-esx.html.  VMware. 2021. VMware ESXi: The Purpose-Built Bare Metal Hyper-visor. https:\/\/www.vmware.com\/products\/esxi-and-esx.html."},{"key":"e_1_3_2_1_124_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-38631-2_15"},{"key":"e_1_3_2_1_125_1","unstructured":"Ric Wheeler. 2021. Homepage of fs_mark. https:\/\/sourceforge.net\/projects\/fsmark\/.  Ric Wheeler. 2021. Homepage of fs_mark. https:\/\/sourceforge.net\/projects\/fsmark\/."},{"key":"e_1_3_2_1_126_1","unstructured":"Will Deacon. 2021. Homepage of kvmtool. https:\/\/github.com\/kvmtool\/kvmtool.  Will Deacon. 2021. Homepage of kvmtool. https:\/\/github.com\/kvmtool\/kvmtool."},{"key":"e_1_3_2_1_127_1","volume-title":"Future Wireless Networks and Information Systems","author":"Xing Yuping","unstructured":"Yuping Xing and Yongzhao Zhan . 2012. Virtualization and cloud computing . In Future Wireless Networks and Information Systems . Springer, Berlin , Heidelberg , 305--312. Yuping Xing and Yongzhao Zhan. 2012. Virtualization and cloud computing. In Future Wireless Networks and Information Systems. Springer, Berlin, Heidelberg, 305--312."},{"key":"e_1_3_2_1_128_1","doi-asserted-by":"publisher","DOI":"10.1109\/SC2.2018.00016"}],"event":{"name":"EuroSys '22: Seventeenth European Conference on Computer Systems","location":"Rennes France","acronym":"EuroSys '22","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the Seventeenth European Conference on Computer Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3492321.3519589","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3492321.3519589","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:31:08Z","timestamp":1750188668000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3492321.3519589"}},"subtitle":["hypervisor-agnostic guest overlays for VMs"],"short-title":[],"issued":{"date-parts":[[2022,3,28]]},"references-count":124,"alternative-id":["10.1145\/3492321.3519589","10.1145\/3492321"],"URL":"https:\/\/doi.org\/10.1145\/3492321.3519589","relation":{},"subject":[],"published":{"date-parts":[[2022,3,28]]},"assertion":[{"value":"2022-03-28","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}