Publication View

Compatibility is Not Transparency: VMM Detection Myths and Realities (2007)

Abstract
Recent work on applications ranging from realistic honeypots to stealthier rootkits has speculated about building transparent VMMs – VMMs that are indistinguishable from native hardware, even to a dedicated adversary. We survey anomalies between real and virtual hardware and consider methods for detecting such anomalies, as well as possible countermeasures. We conclude that building a transparent VMM is fundamentally infeasible, as well as impractical from a performance and engineering standpoint. 1

Publication details
Download http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.77.8567
Source http://www.stanford.edu/~talg/papers/HOTOS07/vmm-detection-hotos07.pdf
Contributors CiteSeerX
Repository CiteSeerX - Scientific Literature Digital Library and Search Engine (United States)
Type text
Language English
Relation 10.1.1.4.9730, 10.1.1.126.4917, 10.1.1.13.3810, 10.1.1.7.1541, 10.1.1.37.1094, 10.1.1.100.224, 10.1.1.3.9013, 10.1.1.72.515, 10.1.1.117.196, 10.1.1.77.957, 10.1.1.105.545, 10.1.1.68.629, 10.1.1.90.8832, 10.1.1.94.2657, 10.1.1.97.7751