List of Topics:
Location Research Breakthrough Possible @S-Logix pro@slogix.in

Office Address

Social List

Virtuoso: Narrowing the Semantic Gap in Virtual Machine Introspection - 2011

Virtuoso: Narrowing the Semantic Gap in Virtual Machine Introspection

Research Area:  Digital Forensics

Abstract:

Introspection has featured prominently in many recent security solutions, such as virtual machine-based intrusion detection, forensic memory analysis, and low-artifact malware analysis. Widespread adoption of these approaches, however, has been hampered by the semantic gap: in order to extract meaningful information about the current state of a virtual machine, detailed knowledge of the guest operating system-s inner workings is required. In this paper, we present a novel approach for automatically creating introspection tools for security applications with minimal human effort. By analyzing dynamic traces of small, in-guest programs that compute the desired introspection information, we can produce new programs that retrieve the same information from outside the guest virtual machine. We demonstrate the efficacy of our techniques by automatically generating 17 programs that retrieve security information across 3 different operating systems, and show that their functionality is unaffected by the compromise of the guest system. Our technique allows introspection tools to be effortlessly generated for multiple platforms, and enables the development of rich introspection-based security applications.

Keywords:  

Author(s) Name:  Brendan Dolan-Gavitt; Tim Leek; Michael Zhivich; Jonathon Giffin; Wenke Lee

Journal name:  

Conferrence name:  IEEE Symposium on Security and Privacy

Publisher name:  IEEE

DOI:  10.1109/SP.2011.11

Volume Information: