Hiding in the Shadows: Empowering ARM for Stealthy Virtual Machine Introspection
Hiding in the Shadows: Empowering ARM for Stealthy Virtual Machine Introspection
复制标题
隐藏在阴影中:赋能 ARM 进行隐形虚拟机自省
DOI:
10.1145/3274694.3274698
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Apostolis Zarras
中科院分区:
文献类型:
--
作者:
Sergej Proskurin;Tamas K. Lengyel;Marius Momeu;C. Eckert;Apostolis Zarras
ARM has become the leading processor architecture for mobile and IoT devices, while it has recently started claiming a bigger slice of the server market pie as well. As such, it will not be long before malware more regularly target the ARM architecture. Therefore, the stealthy operation of Virtual Machine Introspection (VMI) is an obligation to successfully analyze and proactively mitigate this growing threat. Stealthy VMI has proven itself perfectly suitable for malware analysis on Intel's architecture, yet, it often lacks the foundation required to be equally effective on ARM.