• DocumentCode
    2350977
  • Title

    Virtuoso: Narrowing the Semantic Gap in Virtual Machine Introspection

  • Author

    Dolan-Gavitt, Brendan ; Leek, Tim ; Zhivich, Michael ; Giffin, Jonathon ; Lee, Wenke

  • Author_Institution
    Sch. of Comput. Sci., Georgia Inst. of Technol., Atlanta, GA, USA
  • fYear
    2011
  • fDate
    22-25 May 2011
  • Firstpage
    297
  • Lastpage
    312
  • Abstract
    Introspection has featured prominently in many recent security solutions, such as virtual machine-based intrusion detection, forensic memory analysis, and low-artifact malware analysis. Widespread adoption of these approaches, however, has been hampered by the semantic gap: in order to extract meaningful information about the current state of a virtual machine, detailed knowledge of the guest operating system´s inner workings is required. In this paper, we present a novel approach for automatically creating introspection tools for security applications with minimal human effort. By analyzing dynamic traces of small, in-guest programs that compute the desired introspection information, we can produce new programs that retrieve the same information from outside the guest virtual machine. We demonstrate the efficacy of our techniques by automatically generating 17 programs that retrieve security information across 3 different operating systems, and show that their functionality is unaffected by the compromise of the guest system. Our technique allows introspection tools to be effortlessly generated for multiple platforms, and enables the development of rich introspection-based security applications.
  • Keywords
    security of data; virtual machines; forensic memory analysis; malware analysis; operating system; virtual machine introspection; virtual machine-based intrusion detection; virtuoso; Data mining; Kernel; Malware; Training; Virtual machining; dynamic analysis; security; virtual machine introspection; virtualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy (SP), 2011 IEEE Symposium on
  • Conference_Location
    Berkeley, CA
  • ISSN
    1081-6011
  • Print_ISBN
    978-1-4577-0147-4
  • Electronic_ISBN
    1081-6011
  • Type

    conf

  • DOI
    10.1109/SP.2011.11
  • Filename
    5958036