Improving Transparency of Hardware Breakpoints with Virtual Machine Introspection

Improving Transparency of Hardware Breakpoints with Virtual Machine Introspection
复制标题

通过虚拟机自省提高硬件断点的透明度

DOI:
10.1109/iiaiaai55812.2022.00031
复制
发表时间:
2022
期刊:
Proceedings of 2022 11th International Congress on Advanced Applied Informatics (IIAI-AAI 2022)
影响因子:
--
通讯作者:
Taniguchi Hideo
Taniguchi Hideo
中科院分区:
--
文献类型:
--
作者:
Sato Masaya;Nakamura Ryosuke;Yamauchi Toshihiro;Taniguchi Hideo

文献摘要

参考文献

相似文献

硬件断点用于监视虚拟机(VM)上程序的行为。尽管虚拟机监视器(VMM)可以在硬件断点处检查VM上的程序,但程序本身可以通过读取调试寄存器来检测硬件断点。如果检测到硬件断点,恶意程序可能会更改其行为以避免自省和其他安全机制。为了防止自省规避,提出了通过向VM返回假值来隐藏硬件断点的方法。这些方法检测来自VM的调试寄存器的读写操作,然后将处理返回给VM,就好像它们的访问已成功一样。然而,通过确认地址集中调试异常的可用性,VM自检仍然可从VM检测到。虽然前面的工作处理调试寄存器的读写操作,但调试异常不会传递给VM程序。为了解决这一问题,本研究提出了一种使硬件断点与虚拟机自省兼容的方法。该方法使用剩余的调试地址寄存器在VM程序设置的硬件断点处传递调试异常。如果VM程序尝试将值写入调试寄存器,则VMM检测到该值并将其存储在不用于VM自检的实际调试寄存器中。因为硬件断点处的调试异常被传递给了VM,所以由VM设置的硬件断点与VM自省兼容。评估结果表明,该方法具有较低的性能开销。
Hardware breakpoints are used to monitor the behavior of a program on a virtual machine (VM). Although a virtual machine monitor (VMM) can inspect programs on a VM at hardware breakpoints, the programs themselves can detect hardware breakpoints by reading debug registers. Malicious programs may change their behavior to avoid introspection and other security mechanisms if a hardware breakpoint is detected. To prevent introspection evasion, methods for hiding hardware breakpoints by returning a fake value to the VM are proposed. These methods detect the read and write operations of the debug register from the VM and then return the processing to the VM as if their access has succeeded. However, VM introspection remains detectable from the VM by confirming the availability of the debug exception in the address set. While the previous work handles the read and write operations of the debug register, the debug exception is not delivered to the VM program. To address this problem, this study presents a method for making hardware breakpoints compatible with VM introspection. The proposed method uses surplus debug address registers to deliver the debug exception at the hardware breakpoint set by the VM program. If a VM program attempts to write a value to a debug register, the VMM detects and stores the value in a real debug register that is not used for VM introspection. Because debug exception at the hardware breakpoint was delivered to the VM, hardware breakpoints set by the VM were compatible with VM introspection. The evaluation results showed that the proposed method had a low performance overhead.
DOI: 10.1109/jproc.2019.2927919
发表时间: 2019-07
影响因子: 20.6
作者:
Zeyi Tao;Qi Xia;Zijiang Hao;Cheng Li;Lele Ma;Shanhe Yi;Qun A. Li
通讯作者: Zeyi Tao;Qi Xia;Zijiang Hao;Cheng Li;Lele Ma;Shanhe Yi;Qun A. Li
防病毒软件抵御防病毒终结者
DOI: 10.1109/tifs.2012.2206028
发表时间: 2012
影响因子: 6.8
作者:
Fu;Min;Chang;Chi;Chieh
通讯作者: Chieh
DOI: 10.1109/tifs.2018.2883027
发表时间: 2019-06
影响因子: 6.8
作者:
Zhenyu Ning;Fengwei Zhang
通讯作者: Zhenyu Ning;Fengwei Zhang
隐藏在阴影中:赋能 ARM 进行隐形虚拟机自省
DOI: 10.1145/3274694.3274698
发表时间: 2018
期刊: Proceedings of the 34th Annual Computer Security Applications Conference
影响因子: --
作者:
Sergej Proskurin;Tamas K. Lengyel;Marius Momeu;C. Eckert;Apostolis Zarras
通讯作者: Apostolis Zarras