• DocumentCode
    3230088
  • Title

    Using Hardware Features for Increased Debugging Transparency

  • Author

    Fengwei Zhang ; Leach, Kevin ; Stavrou, Angelos ; Haining Wang ; Kun Sun

  • fYear
    2015
  • fDate
    17-21 May 2015
  • Firstpage
    55
  • Lastpage
    69
  • Abstract
    With the rapid proliferation of malware attacks on the Internet, understanding these malicious behaviors plays a critical role in crafting effective defense. Advanced malware analysis relies on virtualization or emulation technology to run samples in a confined environment, and to analyze malicious activities by instrumenting code execution. However, virtual machines and emulators inevitably create artifacts in the execution environment, making these approaches vulnerable to detection or subversion. In this paper, we present MALT, a debugging framework that employs System Management Mode, a CPU mode in the x86 architecture, to transparently study armored malware. MALT does not depend on virtualization or emulation and thus is immune to threats targeting such environments. Our approach reduces the attack surface at the software level, and advances state-of-the-art debugging transparency. MALT embodies various debugging functions, including register/memory accesses, breakpoints, and four stepping modes. We implemented a prototype of MALT on two physical machines, and we conducted experiments by testing an array of existing anti-virtualization, anti-emulation, and packing techniques against MALT. The experimental results show that our prototype remains transparent and undetected against the samples. Furthermore, our prototype of MALT introduces moderate but manageable overheads on both Windows and Linux platforms.
  • Keywords
    Internet; Linux; invasive software; program debugging; software architecture; virtual machines; virtualisation; Internet; Linux platforms; MALT; Windows platforms; debugging transparency; emulation technology; hardware features; malicious behaviors; malware attacks; rapid proliferation; system management mode; virtual machines; virtualization technology; x86 architecture; Debugging; Hardware; Kernel; Malware; Registers; Servers; Virtualization; SMM; malware debugging; transparency;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy (SP), 2015 IEEE Symposium on
  • Conference_Location
    San Jose, CA
  • ISSN
    1081-6011
  • Type

    conf

  • DOI
    10.1109/SP.2015.11
  • Filename
    7163018