Hiding in the Shadows: Empowering ARM for Stealthy Virtual Machine Introspection

Hiding in the Shadows: Empowering ARM for Stealthy Virtual Machine Introspection
复制标题

隐藏在阴影中:赋能 ARM 进行隐形虚拟机自省

DOI:
10.1145/3274694.3274698
复制
发表时间:
2018
期刊:
Proceedings of the 34th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Apostolis Zarras
Apostolis Zarras
中科院分区:
--
文献类型:
--
作者:
Sergej Proskurin;Tamas K. Lengyel;Marius Momeu;C. Eckert;Apostolis Zarras

文献摘要

被引文献

相似文献

ARM已成为移动设备和IoT设备的领先处理器体系结构,而它最近也开始声称服务器市场上的更大片段。因此,不久之后,恶意软件更定期地针对ARM架构。因此,虚拟机内省(VMI)的隐身操作是成功分析和主动减轻这种日益增长的威胁的义务。隐形VMI已证明自己非常适合针对英特尔体系结构的恶意软件分析,但是,它通常缺乏在ARM上同样有效的基础。
ARM has become the leading processor architecture for mobile and IoT devices, while it has recently started claiming a bigger slice of the server market pie as well. As such, it will not be long before malware more regularly target the ARM architecture. Therefore, the stealthy operation of Virtual Machine Introspection (VMI) is an obligation to successfully analyze and proactively mitigate this growing threat. Stealthy VMI has proven itself perfectly suitable for malware analysis on Intel's architecture, yet, it often lacks the foundation required to be equally effective on ARM.