Stealthy malware detection and monitoring through VMM-based “out-of-the-box” semantic view reconstruction

Stealthy malware detection and monitoring through VMM-based “out-of-the-box” semantic view reconstruction
复制标题

DOI:
10.1145/1698750.1698752
复制
发表时间:
2010-02
期刊:
ACM Trans. Inf. Syst. Secur.
影响因子:
--
通讯作者:
Xuxian Jiang;Xinyuan Wang;Dongyan Xu
Xuxian Jiang;Xinyuan Wang;Dongyan Xu
中科院分区:
其他
文献类型:
--
作者:
Xuxian Jiang;Xinyuan Wang;Dongyan Xu

文献摘要

被引文献

相似文献

在最近的恶意软件事件中,一个令人震惊的趋势是,它们配备了隐形技术来检测、规避和破坏受害者的恶意软件检测设施。在防御方面,传统的基于主机的反恶意软件系统的一个基本限制是,它们在它们所保护的主机(“盒中”)内运行,使它们容易受到恶意软件的反检测和颠覆。为了解决这一限制,最近的基于虚拟机(VM)技术的解决方案主张将恶意软件检测工具放置在受保护的VM之外(“开箱即用”)。然而,它们获得了对篡改的抵抗力,代价是失去了宿主的内部语义视图,而这是“在盒子里”的方法所享有的。这带来了一个被称为语义鸿沟的技术挑战。在本文中,我们介绍了VMwatcher的设计、实现和评估--这是一种克服语义鸿沟挑战的“开箱即用”方法。开发了一种名为来宾视图转换的新技术,以从外部非侵入性地重建VM的内部语义视图(例如,文件、进程和核心模块)。更具体地说,新技术将来宾操作系统数据结构和函数的语义定义投射到虚拟机监视器(VMM)级的VM状态上,从而可以重构语义视图。此外,我们扩展了来宾视图强制转换以重构VM中的系统调用事件的细节(例如,进行系统调用的进程以及系统调用号、参数和返回值),从而丰富了语义视图。随着语义差距的有效缩小,我们确定了三种独特的恶意软件检测和监控功能:(I)基于视图比较的恶意软件检测及其在Rootkit检测中的演示;(Ii)现成的反恶意软件软件的现成部署,提高了检测精度和防篡改能力;以及(Iii)针对恶意软件和入侵行为的非侵入式系统调用监控。我们已经在许多VMM平台上实现了一个概念验证VMwatch原型。我们对真实世界恶意软件的评估实验,包括难以捉摸的内核级Rootkit,证明了VMWatcher的实用性和有效性。
An alarming trend in recent malware incidents is that they are armed with stealthy techniques to detect, evade, and subvert malware detection facilities of the victim. On the defensive side, a fundamental limitation of traditional host-based antimalware systems is that they run inside the very hosts they are protecting (“in-the-box”), making them vulnerable to counter detection and subversion by malware. To address this limitation, recent solutions based on virtual machine (VM) technologies advocate placing the malware detection facilities outside of the protected VM (“out-of-the-box”). However, they gain tamper resistance at the cost of losing the internal semantic view of the host, which is enjoyed by “in-the-box” approaches. This poses a technical challenge known as the semantic gap. In this article, we present the design, implementation, and evaluation of VMwatcher—an “out-of-the-box” approach that overcomes the semantic gap challenge. A new technique called guest view casting is developed to reconstruct internal semantic views (e.g., files, processes, and kernel modules) of a VM nonintrusively from the outside. More specifically, the new technique casts semantic definitions of guest OS data structures and functions on virtual machine monitor (VMM)-level VM states, so that the semantic view can be reconstructed. Furthermore, we extend guest view casting to reconstruct details of system call events (e.g., the process that makes the system call as well as the system call number, parameters, and return value) in the VM, enriching the semantic view. With the semantic gap effectively narrowed, we identify three unique malware detection and monitoring capabilities: (i) view comparison-based malware detection and its demonstration in rootkit detection; (ii) “out-of-the-box” deployment of off-the-shelf anti malware software with improved detection accuracy and tamper-resistance; and (iii) nonintrusive system call monitoring for malware and intrusion behavior observation. We have implemented a proof-of-concept VMwatcher prototype on a number of VMM platforms. Our evaluation experiments with real-world malware, including elusive kernel-level rootkits, demonstrate VMwatcher's practicality and effectiveness.