Improving Transparency of Hardware Breakpoints with Virtual Machine Introspection
Improving Transparency of Hardware Breakpoints with Virtual Machine Introspection
复制标题
通过虚拟机自省提高硬件断点的透明度
DOI:
10.1109/iiaiaai55812.2022.00031
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Taniguchi Hideo
中科院分区:
文献类型:
--
作者:
Sato Masaya;Nakamura Ryosuke;Yamauchi Toshihiro;Taniguchi Hideo
Hardware breakpoints are used to monitor the behavior of a program on a virtual machine (VM). Although a virtual machine monitor (VMM) can inspect programs on a VM at hardware breakpoints, the programs themselves can detect hardware breakpoints by reading debug registers. Malicious programs may change their behavior to avoid introspection and other security mechanisms if a hardware breakpoint is detected. To prevent introspection evasion, methods for hiding hardware breakpoints by returning a fake value to the VM are proposed. These methods detect the read and write operations of the debug register from the VM and then return the processing to the VM as if their access has succeeded. However, VM introspection remains detectable from the VM by confirming the availability of the debug exception in the address set. While the previous work handles the read and write operations of the debug register, the debug exception is not delivered to the VM program. To address this problem, this study presents a method for making hardware breakpoints compatible with VM introspection. The proposed method uses surplus debug address registers to deliver the debug exception at the hardware breakpoint set by the VM program. If a VM program attempts to write a value to a debug register, the VMM detects and stores the value in a real debug register that is not used for VM introspection. Because debug exception at the hardware breakpoint was delivered to the VM, hardware breakpoints set by the VM were compatible with VM introspection. The evaluation results showed that the proposed method had a low performance overhead.
登录
查看更多内容
影响因子:
20.6
作者:
Zeyi Tao;Qi Xia;Zijiang Hao;Cheng Li;Lele Ma;Shanhe Yi;Qun A. Li
通讯作者:
Zeyi Tao;Qi Xia;Zijiang Hao;Cheng Li;Lele Ma;Shanhe Yi;Qun A. Li
DOI:
10.1109/tifs.2012.2206028
发表时间:
2012
影响因子:
6.8
作者:
Fu;Min;Chang;Chi;Chieh
通讯作者:
Chieh
DOI:
10.1109/tifs.2018.2883027
发表时间:
2019-06
影响因子:
6.8
作者:
Zhenyu Ning;Fengwei Zhang
通讯作者:
Zhenyu Ning;Fengwei Zhang
DOI:
10.1145/3274694.3274698
发表时间:
2018
期刊:
Proceedings of the 34th Annual Computer Security Applications Conference
影响因子:
--
作者:
Sergej Proskurin;Tamas K. Lengyel;Marius Momeu;C. Eckert;Apostolis Zarras
通讯作者:
Apostolis Zarras