Title :
Process Implanting: A New Active Introspection Framework for Virtualization
Author :
Gu, Zhongshu ; Deng, Zhui ; Xu, Dongyan ; Jiang, Xuxian
Author_Institution :
Dept. of Comput. Sci., Purdue Univ., West Lafayette, IN, USA
Abstract :
Previous research on virtual machine introspection proposed "out-of-box" approach by moving out security tools from the guest operating system. However, compared to the traditional "in-the-box" approach, it remains a challenge to obtain a complete semantic view due to the semantic gap between the guest VM and the hyper visor. In this paper, we present Process Implanting, a new active VM introspection framework, to narrow the semantic gap by implanting a process from the host into the guest VM and executing it under the cover of an existing running process. With the protection and coordination from the hyper visor, the implanted process can run with a degree of stealthiest and exit gracefully without leaving negative impact on the guest operating system. We have designed and implemented a proof-of-concept prototype on KVM which leverages hardware virtualization. We also propose and demonstrate application scenarios for Process Implanting in the area of VM security.
Keywords :
operating systems (computers); security of data; virtual machines; virtualisation; KVM; active introspection framework; guest operating system; hypervisor; process implanting; security tools; virtual machine introspection; virtualization; Context; Instruction sets; Kernel; Malware; Switches; Virtual machine monitors; Active VM introspection; Security; Virtualization;
Conference_Titel :
Reliable Distributed Systems (SRDS), 2011 30th IEEE Symposium on
Conference_Location :
Madrid
Print_ISBN :
978-1-4577-1349-1
DOI :
10.1109/SRDS.2011.26