arrow
返回

Detecting Hardware-Assisted Virtualization With Inconspicuous Features

delete2021-01-01
delete9
PRE
AI
Z
Zhi Zhang *
Y
Yueqiang Cheng
高
高艳松 (Yansong Gao)
‪
‪Surya Nepal‬
刘东喜 封面图
刘东喜 (Dongxi Liu)
Y
Yi Zou
DOI:10.1109/TIFS.2020.3004264delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Recent years have witnessed the proliferation of the deployment of virtualization techniques. Virtualization is designed to be transparent, that is, unprivileged users should not be able to detect whether a system is virtualized. Such detection can result in serious security threats such as evading virtual machine (VM)-based malware dynamic analysis and exploiting vulnerabilities for cross-VM attacks. The traditional software-based virtualization leaves numerous artifacts/fingerprints, which can be exploited without much effort to detect the virtualization. In contrast, current mainstream hardware-assisted virtualization significantly enhances the virtualization transparency, making itself more transparent and difficult to be detected. Nonetheless, we showcase three new identified low-level inconspicuous features, which can be leveraged by an unprivileged adversary to effectively and stealthily detect the hardware-assisted virtualization. All three features come from the chipset fingerprints, rather than the traces of software-based virtualization implementations (e.g., Xen or KVM). The identified features include i) Translation-Lookaside Buffer (TLB) stores an extra layer of address translations; ii) Last-Level Cache (LLC) caches one more layer of page-table entries; and iii) Level-1 Data (L1D) Cache is unstable. Based on the above features, we develop three corresponding virtualization detection techniques, which are then comprehensively evaluated on three native environments and three popular cloud providers: i) Amazon Elastic Compute Cloud, ii) Google Compute Engine and iii) Microsoft Azure. Experimental results validate that these three adversarial detection techniques are effective (with no false positive) and stealthy (without triggering suspicious system events, e.g., VM-exit) in detecting the above commodity virtualized environments.
Keyword:
Virtualization-based malware analysis
microarchitectural timing
virtual machine-based rootkit
virtualization detection
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.3K
被引数:
2.3W

机构

I
intel usa
学者数:
736
论文数: 548
被引数: 1
C
引用论文

引用论文

Protocatechuate 3,4-dioxygenase: comparative study of inhibition and active-site interactions of pyridine N-oxides
err2002-05-01
err0
PREAI
errSheldon W. May; Patricia W. Mueller; Charlie D. Oldham; Cynthia K. Williamson; Anne L. Sowell
err分享
err收藏
err分享
err收藏
Comparative study between pulsed and continuous wave lasers for Photofrin® photodynamic therapy
err2005-10-19
err0
PREAI
errMasoud Panjehpour; Bergein F. Overholt; Robert C. Denovo; Mark G. Petersen; Rick E. Sneed
err分享
err收藏
Infection and Microbiome: Impact of Tuberculosis on Human Gut Microbiome of Indian Cohort
err2018-01-18
err0
errOAAI
errUtkarsh Sood; Abhay Bajaj; Roshan Kumar; Sachin Khurana; Vipin Chandra Kalia
err分享
err收藏
err分享
err收藏
学者 查看更多内容