Virtualization-based System Hardening against Untrusted Kernels