Publication View

Compatibility is Not Transparency: VMM Detection Myths and Realities (2007)

Abstract
Abstract Recent work on applications ranging from realistic hon-eypots to stealthier rootkits has speculated about building transparent VMMs- VMMs that are indistinguishablefrom native hardware, even to a dedicated adversary. We survey anomalies between real and virtual hardware andconsider methods for detecting such anomalies, as well as possible countermeasures. We conclude that build-ing a transparent VMM is fundamentally infeasible, as well as impractical from a performance and engineeringstandpoint.

Publication details
Download http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.142.8678
Source http://www.stanford.edu/~talg/papers/HOTOS07/vmm-detection-hotos07.ps
Contributors CiteSeerX
Repository CiteSeerX - Scientific Literature Digital Library and Search Engine (United States)
Type text
Language English
Relation 10.1.1.4.9730, 10.1.1.126.4917, 10.1.1.13.3810, 10.1.1.7.1541, 10.1.1.37.1094, 10.1.1.100.224, 10.1.1.3.9013, 10.1.1.6.1338, 10.1.1.117.196, 10.1.1.77.957, 10.1.1.94.2657, 10.1.1.141.1890, 10.1.1.105.545, 10.1.1.68.629, 10.1.1.90.8832, 10.1.1.97.7751