OM Esoul
VMX-rootkit : implementing malware with hardware virtual machine extensions
Esoul, OM
Authors
Contributors
GS Cooper G.S.Cooper@salford.ac.uk
Supervisor
Abstract
Stealth Malware (Rootkit) is a malicious software used by attack-
ers who wish to run their code on a compromised computer with-
out being detected. Over the years, rootkits have targeted differ-
ent operating systems and have used different techniques and mecha-
nisms to avoid detection. In late 2005 and early 2006, both, Intel™
and AMD™ incorporated explicit hardware support for virtualiza-
tion into their CPUs. While this hardware support can help sim-
plify the design and the implementation of a light-weight and efficient
Virtual Machine Monitors (VMMs), this technology has introduced
a new powerful mechanism that can be used by malware to create
extremely stealthy rootkit called hardware-assisted virtual machine
rootkit (HVM rootkit). An HVM rootkit is capable of totally control-
ling a compromised system by installing a small VMM (a.k.a. hyper-
visor) underneath the operating system and its applications without
altering any part of the target operating system or any part of its
applications. It places the existing operating system into a virtual
machine and turns it into a guest operating system on-the-fly without
a reboot. The guest operating system is then totally governed and
manipulated by the malicious hypervisor.
In this thesis I have investigated the design and implementation of
a minimal hypervisor based Rootkit that takes advantage of Intel
Visualization Technology (Intel VT) for the IA-32 architecture (VT-
x ) and Microsoft Windows XP SP2 as the target operating system.
Citation
Esoul, O. VMX-rootkit : implementing malware with hardware virtual machine extensions. (Thesis). Salford : University of Salford
Thesis Type | Thesis |
---|---|
Deposit Date | Oct 3, 2012 |
Additional Information | Additional Information : Located in the Secure Room |
Award Date | Jan 1, 2008 |
This file is under embargo due to copyright reasons.
Contact Library-ThesesRequest@salford.ac.uk to request a copy for personal use.
Downloadable Citations
About USIR
Administrator e-mail: library-research@salford.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2025
Advanced Search