DocumentCode :
2744113
Title :
Assessment of Virtualization as a Sensor Technique
Author :
Narvaez, Julia ; Aval, Chiraag ; Endicott-Popovsky, Barbara ; Seifert, Christian ; Malviya, Ashish K. ; Nordwall, Douglas
fYear :
2010
fDate :
20-20 May 2010
Firstpage :
61
Lastpage :
65
Abstract :
The explosive growth of malware development and the increasing sophistication of malware behavior require thatsecurity researchers be on the lookout for new vectors of attacks. Drive-by-downloads are among the types of attacks that are onthe rise. To study them, researchers use client honeypots deployed in virtualized environments; however, virtualization isdetectable. There is evidence of malware detecting virtualization and hiding its malicious intent to avoid detection and furtherstudy. This research aims to identify differences in detection capabilities of honeypots deployed in two different environments,those deployed in virtual machines and those deployed in physical machines. With this objective, these researchers developed abare-metal honeypot that does not use virtualization. The honeypots deployed in both environments accessed malicious URLs andclassified them. Discrepancies in the resulting classification were analyzed. Accomplishments include the identification of anexperimental methodology to be scaled for a larger study during the next phase of this research.Keywords- honeypot; virtual machine; cyber-security; malware; malware analysis; virtualization; virtualization
Keywords :
Computer security; Digital forensics; Explosives; Information security; Internet; Uniform resource locators; Virtual environment; Virtual machining; Web pages; Web server; cyber-security; honeypot; malware; malware analysis; virtual machine; virtualization; virtualization detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Systematic Approaches to Digital Forensic Engineering (SADFE), 2010 Fifth IEEE International Workshop on
Conference_Location :
Oakland, CA, USA
Print_ISBN :
978-0-7695-4052-8
Type :
conf
DOI :
10.1109/SADFE.2010.16
Filename :
5491884
Link To Document :
بازگشت