DocumentCode
2744113
Title
Assessment of Virtualization as a Sensor Technique
Author
Narvaez, Julia ; Aval, Chiraag ; Endicott-Popovsky, Barbara ; Seifert, Christian ; Malviya, Ashish K. ; Nordwall, Douglas
fYear
2010
fDate
20-20 May 2010
Firstpage
61
Lastpage
65
Abstract
The explosive growth of malware development and the increasing sophistication of malware behavior require thatsecurity researchers be on the lookout for new vectors of attacks. Drive-by-downloads are among the types of attacks that are onthe rise. To study them, researchers use client honeypots deployed in virtualized environments; however, virtualization isdetectable. There is evidence of malware detecting virtualization and hiding its malicious intent to avoid detection and furtherstudy. This research aims to identify differences in detection capabilities of honeypots deployed in two different environments,those deployed in virtual machines and those deployed in physical machines. With this objective, these researchers developed abare-metal honeypot that does not use virtualization. The honeypots deployed in both environments accessed malicious URLs andclassified them. Discrepancies in the resulting classification were analyzed. Accomplishments include the identification of anexperimental methodology to be scaled for a larger study during the next phase of this research.Keywords- honeypot; virtual machine; cyber-security; malware; malware analysis; virtualization; virtualization
Keywords
Computer security; Digital forensics; Explosives; Information security; Internet; Uniform resource locators; Virtual environment; Virtual machining; Web pages; Web server; cyber-security; honeypot; malware; malware analysis; virtual machine; virtualization; virtualization detection;
fLanguage
English
Publisher
ieee
Conference_Titel
Systematic Approaches to Digital Forensic Engineering (SADFE), 2010 Fifth IEEE International Workshop on
Conference_Location
Oakland, CA, USA
Print_ISBN
978-0-7695-4052-8
Type
conf
DOI
10.1109/SADFE.2010.16
Filename
5491884
Link To Document