DocumentCode
691807
Title
Towards Implicitly Introspecting the Preinstalled Operating System with Local-Booting Virtualization Technology
Author
Yan Wen ; Jinjing Zhao ; Hua Chen ; Minhuan Huang
Author_Institution
Beijing Inst. of Syst. Eng., Beijing, China
fYear
2013
fDate
21-22 Dec. 2013
Firstpage
31
Lastpage
38
Abstract
The virtual machine (VM) based introspection on the operating system (OS) holds predominance over previous host-based introspectors for being more resistant to attack while suffering the difficulty of retrieving the semantic view of the OS. Previous approaches addressing this limitation highly depend on the explicit guest information which is still subvertable to the privileged malware. Moreover, they only deal with the OS deployed in the VM instead of our daily used native OS. In this paper, we present a new VM-based introspecting approach called Pisces which accurately reproduces the execution environment of the underlying preinstalled OS within the Pisces VM and provides an OS-level semantic view. With our novel local-booting virtualization technology, Pisces VM just boots from the underlying host OS but not a newly installed OS image. Thus, Pisces provides a feasible way to introspect on the existing OS. In addition, instead of relying on the explicit guest information, Pisces adopts a set of unique techniques to implicitly construct the semantic view of the OS from within the virtualized hardware layer. The evaluation results demonstrate its practicality and effectiveness.
Keywords
invasive software; operating systems (computers); virtual machines; virtualisation; OS; Pisces VM; host-based introspectors; local-booting virtualization technology; preinstalled operating system; privileged malware; virtual machine; File systems; Hardware; Indexes; Malware; Program processors; Semantics; Virtual machining; implicit-introspection; malware; virtual machine; virtual machine monitor;
fLanguage
English
Publisher
ieee
Conference_Titel
Dependable, Autonomic and Secure Computing (DASC), 2013 IEEE 11th International Conference on
Conference_Location
Chengdu
Print_ISBN
978-1-4799-3380-8
Type
conf
DOI
10.1109/DASC.2013.34
Filename
6844334
Link To Document