Stealthy Malware Detection Through VMM-Based "Out-of-the-Box" Semantic View Reconstruction

Source: Association for Computing Machinery

Favorite

Free registration required

An alarming trend in malware attacks is that they are armed with stealthy techniques to detect, evade, and subvert malware detection facilities of the victim. On the defensive side, a fundamental limitation of traditional host-based anti-malware systems is that they run inside the very hosts they are protecting ("In the box"), making them vulnerable to counter-detection and subversion by malware. To address this limitation, recent solutions based on Virtual Machine (VM) technologies advocate placing the malware detection facilities outside of the protected VM ("Out of the box"). However, they gain tamper resistance at the cost of losing the native, semantic view of the host which is enjoyed by the "In the box" approach, thus leading to a technical challenge known as the semantic gap.
Format:PDF Size:708.40
Date:Nov 2007