A universal semantic bridge for virtual machine introspection

Christian Schneider, Jonas Pfoh, Claudia Eckert

Publikation: Beitrag in Buch/Bericht/KonferenzbandKonferenzbeitragBegutachtung

6 Zitate (Scopus)

Abstract

All systems that utilize virtual machine introspection (VMI) need to overcome the disconnect between the low-level state that the hypervisor sees and its semantics within the guest. This problem has become well-known as the semantic gap. In this work, we introduce our tool, InSight, that establishes a semantic connection between the guest and the hypervisor independent of the application at hand. InSight goes above and beyond previous approaches in that it strives to expose all kernel objects to an application with as little human effort as possible. It features a shell interface for interactive inspection as well as a scripting engine for comfortable and safe development of new VMI-based methods. Due to this flexibility, InSight supports a wide variety of VMI applications, such as intrusion detection, forensic analysis, malware analysis, and kernel debugging.

OriginalspracheEnglisch
TitelInformation Systems Security - 7th International Conference, ICISS 2011, Proceedings
Seiten370-373
Seitenumfang4
DOIs
PublikationsstatusVeröffentlicht - 2011
Veranstaltung7th International Conference on Information Systems Security, ICISS 2011 - Kolkata, Indien
Dauer: 15 Dez. 201119 Dez. 2011

Publikationsreihe

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Band7093 LNCS
ISSN (Print)0302-9743
ISSN (elektronisch)1611-3349

Konferenz

Konferenz7th International Conference on Information Systems Security, ICISS 2011
Land/GebietIndien
OrtKolkata
Zeitraum15/12/1119/12/11

Fingerprint

Untersuchen Sie die Forschungsthemen von „A universal semantic bridge for virtual machine introspection“. Zusammen bilden sie einen einzigartigen Fingerprint.

Dieses zitieren