Title
Hypervisor Introspection: A Technique for Evading Passive Virtual Machine Monitoring
Abstract
Security requirements in the cloud have led to the development of new monitoring techniques that can be broadly categorized as virtual machine introspection (VMI) techniques. VMI monitoring aims to provide high-fidelity monitoring while keeping the monitor secure by leveraging the isolation provided by virtualization. This work shows that not all hypervisor activity is hidden from the guest virtual machine (VM), and the guest VM can detect when the hypervisor performs an action on the guest VM, such as a VMI monitoring check. We call this technique hypervisor introspection and demonstrate how a malicious insider could utilize this technique to evade a passive VMI system.
Year
Venue
Field
2015
WOOT
Virtualization,Introspection,Virtual machine introspection,Virtual machine,Storage hypervisor,Hypervisor,Side channel attack,Engineering,Operating system,Embedded system,Cloud computing
DocType
Citations 
PageRank 
Conference
8
0.48
References 
Authors
11
5
Name
Order
Citations
PageRank
Gary Wang192.86
Zachary John Estrada281.15
Cuong Manh Pham380.82
Zbigniew Kalbarczyk41896159.48
Ravishankar K. Iyer53489504.32