• DocumentCode
    2744113
  • Title

    Assessment of Virtualization as a Sensor Technique

  • Author

    Narvaez, Julia ; Aval, Chiraag ; Endicott-Popovsky, Barbara ; Seifert, Christian ; Malviya, Ashish K. ; Nordwall, Douglas

  • fYear
    2010
  • fDate
    20-20 May 2010
  • Firstpage
    61
  • Lastpage
    65
  • Abstract
    The explosive growth of malware development and the increasing sophistication of malware behavior require thatsecurity researchers be on the lookout for new vectors of attacks. Drive-by-downloads are among the types of attacks that are onthe rise. To study them, researchers use client honeypots deployed in virtualized environments; however, virtualization isdetectable. There is evidence of malware detecting virtualization and hiding its malicious intent to avoid detection and furtherstudy. This research aims to identify differences in detection capabilities of honeypots deployed in two different environments,those deployed in virtual machines and those deployed in physical machines. With this objective, these researchers developed abare-metal honeypot that does not use virtualization. The honeypots deployed in both environments accessed malicious URLs andclassified them. Discrepancies in the resulting classification were analyzed. Accomplishments include the identification of anexperimental methodology to be scaled for a larger study during the next phase of this research.Keywords- honeypot; virtual machine; cyber-security; malware; malware analysis; virtualization; virtualization
  • Keywords
    Computer security; Digital forensics; Explosives; Information security; Internet; Uniform resource locators; Virtual environment; Virtual machining; Web pages; Web server; cyber-security; honeypot; malware; malware analysis; virtual machine; virtualization; virtualization detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Systematic Approaches to Digital Forensic Engineering (SADFE), 2010 Fifth IEEE International Workshop on
  • Conference_Location
    Oakland, CA, USA
  • Print_ISBN
    978-0-7695-4052-8
  • Type

    conf

  • DOI
    10.1109/SADFE.2010.16
  • Filename
    5491884