• DocumentCode
    691807
  • Title

    Towards Implicitly Introspecting the Preinstalled Operating System with Local-Booting Virtualization Technology

  • Author

    Yan Wen ; Jinjing Zhao ; Hua Chen ; Minhuan Huang

  • Author_Institution
    Beijing Inst. of Syst. Eng., Beijing, China
  • fYear
    2013
  • fDate
    21-22 Dec. 2013
  • Firstpage
    31
  • Lastpage
    38
  • Abstract
    The virtual machine (VM) based introspection on the operating system (OS) holds predominance over previous host-based introspectors for being more resistant to attack while suffering the difficulty of retrieving the semantic view of the OS. Previous approaches addressing this limitation highly depend on the explicit guest information which is still subvertable to the privileged malware. Moreover, they only deal with the OS deployed in the VM instead of our daily used native OS. In this paper, we present a new VM-based introspecting approach called Pisces which accurately reproduces the execution environment of the underlying preinstalled OS within the Pisces VM and provides an OS-level semantic view. With our novel local-booting virtualization technology, Pisces VM just boots from the underlying host OS but not a newly installed OS image. Thus, Pisces provides a feasible way to introspect on the existing OS. In addition, instead of relying on the explicit guest information, Pisces adopts a set of unique techniques to implicitly construct the semantic view of the OS from within the virtualized hardware layer. The evaluation results demonstrate its practicality and effectiveness.
  • Keywords
    invasive software; operating systems (computers); virtual machines; virtualisation; OS; Pisces VM; host-based introspectors; local-booting virtualization technology; preinstalled operating system; privileged malware; virtual machine; File systems; Hardware; Indexes; Malware; Program processors; Semantics; Virtual machining; implicit-introspection; malware; virtual machine; virtual machine monitor;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable, Autonomic and Secure Computing (DASC), 2013 IEEE 11th International Conference on
  • Conference_Location
    Chengdu
  • Print_ISBN
    978-1-4799-3380-8
  • Type

    conf

  • DOI
    10.1109/DASC.2013.34
  • Filename
    6844334