Publication View

Compatibility is Not Transparency: VMM Detection Myths and Realities (2007)

Abstract
Abstract Recent work on applications ranging from realistic hon-eypots to stealthier rootkits has speculated about building transparent VMMs- VMMs that are indistinguishablefrom native hardware, even to a dedicated adversary. We survey anomalies between real and virtual hardware andconsider methods for detecting such anomalies, as well as possible countermeasures. We conclude that build-ing a transparent VMM is fundamentally infeasible, as well as impractical from a performance and engineeringstandpoint.

Publication details
Download http://citeseerx.ist.psu.edu/viewdoc/summary?doi=?doi=10.1.1.137.320
Source http://www.cs.cmu.edu/~jfrankli/hotos07/vmm_detection_hotos07.ps
Contributors CiteSeerX
Repository CiteSeerX - Scientific Literature Digital Library and Search Engine (United States)
Type text
Language English
Relation 10.1.1.13.3810, 10.1.1.126.4917, 10.1.1.3.9013, 10.1.1.6.1338, 10.1.1.100.224, 10.1.1.117.196, 10.1.1.77.957, 10.1.1.105.545, 10.1.1.68.629, 10.1.1.90.8832, 10.1.1.94.2657, 10.1.1.97.7751