2015Unpublished venueRequires access

Malicious hypervisor and hidden virtualization of operation systems

Anton Sergeev, Victor Minchenkov, Vladimir Bashun

Open publisher page 2 citations

Abstract

Today virtualization technology is the focus of many new potential threats and introduces new security challenges that we must meet. The key problem is that malware can utilize the virtualization techniques of modern CPUs for “hidden virtualization” (invisible for user): to execute as a hypervisor and transform the working operation system (OS) into a “guest” state. In this work we analyzed and compared the functionality of several research virtual machine monitors (VMMs: BluePill, SubVirt, BitVisor) which can be used for hidden virtualization attack. A typical life circle of the hardware-accelerated VMM and mechanisms of hidden virtualization were also described. We also implemented the proof-of-concept prototype of research VMM and used it for tests with hidden virtualization of Linux operation systems. Our measurements demonstrated that malicious VMMs could efficiently hide their presence using hardware-accelerating technologies.

About this research paper

What this paper is about

Today virtualization technology is the focus of many new potential threats and introduces new security challenges that we must meet. The key problem is that malware can utilize the virtualization techniques of modern CPUs for “hidden virtualization” (invisible for user): to execute as a hypervisor and transform the working operation system (OS) into a “guest” state. In this work we analyzed and compared the functionality of several research virtual machine monitors (VMMs: BluePill, SubVirt, BitVisor) which can be used for hidden virtualization attack. A typical life circle of the hardware-accelerated VMM and mechanisms of hidden virtualization were also described. We also implemented the proof-of-concept prototype of research VMM and used it for tests with hidden virtualization of Linux operation systems. Our measurements demonstrated that malicious VMMs could efficiently hide their presence using hardware-accelerating technologies.

Why it matters

OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Today virtualization technology is the focus of many new potential threats and introduces new security challenges that we must meet. The key problem is that malware can utilize the virtualization techniques of modern CPUs for “hidden virtualization” (invisible for user): to execute as a hypervisor and transform the working operation system (OS) into a “guest” state. In this work we analyzed and compared the functionality of several research virtual machine monitors (VMMs: BluePill, SubVirt, BitVisor) which can be used for hidden virtualization attack. A typical life circle of the hardware-accelerated VMM and mechanisms of hidden virtualization were also described. We also implemented the proof-of-concept prototype of research VMM and used it for tests with hidden virtualization of Linux operation systems. Our measurements demonstrated that malicious VMMs could efficiently hide their presence using hardware-accelerating technologies.

Key concepts: Hypervisor, Virtualization, Operating system, Computer science, Full virtualization, Application virtualization, Hardware virtualization, Virtual machine

Related papers

Back to paper searchBrowse research topicsOriginal source
Malicious hypervisor and hidden virtualization of operation systems — Research Paper | ScholarLens