You are here
Hypervisor-based Memory Introspection at the Next Level: User-Mode Memory Introspection and Protection of Live VMs
Andrei Vlad Lutas, Bitdefender
We are living in an era when advanced malware and APTs are trying day-by-day to steal our money, get away with our confidential data, or allow unknown foreign state-sponsored entities to take full control over our systems. With the growing ineffectiveness of traditional anti-malware solutions, it became more than obvious that the industry needs to employ game-changing technologies: we need to get security to a next level. While the support for hardware virtualization becomes generally available on a large variety of platforms, security software taking advantage of it still needs to evolve to be ready for wide scale adoption. While kernel memory introspection, capable of providing rootkit protection is well known in the academia, we've taken the idea beyond the current state-of-the-art providing synchronous, real-time protection for live-VMs against a wide scale of threats. We provide advanced protection also for user-mode processes, while running our solution below the OS, securely isolated against kernel mode attacks. Among others, our approach features stacks & heaps execution prevention, detours prevention and code injection prevention inside protected processes. I will talk about the challenges we faced to get there, some of the key results we obtained, what are the remaining roadblocks, and finally, highlight also how I see the next few years.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Andrei Vlad Lutas},
title = {Hypervisor-based Memory Introspection at the Next Level: {User-Mode} Memory Introspection and Protection of Live {VMs}},
year = {2015},
address = {Santa Clara, CA},
publisher = {USENIX Association},
month = jul
}
connect with us