首页> 外文会议>Computer Security Applications Conference, 2009. ACSAC '09 >MAVMM: Lightweight and Purpose Built VMM for Malware Analysis
【24h】

MAVMM: Lightweight and Purpose Built VMM for Malware Analysis

机译:MAVMM:用于恶意软件分析的轻量级和专用VMM

获取原文

摘要

Malicious software is rampant on the Internet and costs billions of dollars each year. Safe and thorough analysis of malware is key to protecting vulnerable systems and cleaning those that have already been infected. Most current state-of-the-art analysis platforms run alongside the malware, increasing their detectability. This reduces the value of analysis because some malware is known to behave differently when being analyzed. Virtualization offers a compelling platform for malware analysis, with strong isolation and the ability to save and restore guest state. Current virtual machine monitors (VMMs), however, are not designed for malware analysis. Due to their complexity, they often fail to provide transparency and even expose vulnerabilities which could be exploited by the malware running inside guest system. We propose a lightweight VMM (namely MAVMM) that is designed specially for a single job: malware analysis. MAVMM does not implement unnecessary virtualization features commonly found in general purpose hypervisors, including virtual device emulation. We take advantage of hardware virtualization support to make MAVMM more simple, secure and transparent. In this paper, we describe the design and implementation of MAVMM, and the features that we can extract from programs running inside the guest OS. We evaluate our platform in three aspects: functionality, detectability and performance. We show that our system can extract useful information from malicious software, and that it is not susceptible to known virtualization detection techniques.
机译:恶意软件在互联网上猖ramp,每年花费数十亿美元。安全彻底地分析恶意软件是保护易受攻击的系统并清除已感染系统的关键。当前大多数最先进的分析平台都与恶意软件一起运行,从而提高了可检测性。这降低了分析的价值,因为已知某些恶意软件在进行分析时会表现出不同的行为。虚拟化为恶意软件分析提供了一个引人注目的平台,具有强大的隔离能力以及保存和还原来宾状态的能力。但是,当前的虚拟机监视器(VMM)不适用于恶意软件分析。由于它们的复杂性,它们通常无法提供透明性,甚至无法揭示来宾系统内部运行的恶意软件所利用的漏洞。我们提出了一种轻量级的VMM(即MAVMM),该VMM专为一项工作而设计:恶意软件分析。 MAVMM不会实现通用虚拟机管理程序中常见的不必要的虚拟化功能,包括虚拟设备仿真。我们利用硬件虚拟化支持,使MAVMM更加简单,安全和透明。在本文中,我们描述了MAVMM的设计和实现,以及可以从来宾OS内运行的程序中提取的功能。我们从三个方面评估我们的平台:功能,可检测性和性能。我们证明了我们的系统可以从恶意软件中提取有用的信息,并且它不受已知的虚拟化检测技术的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号