ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Virtual rootkits not a problem, claim researchers

Tom Espiner ZDNet.co.uk

Published: 02 Oct 2007 16:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Rootkits that use virtualisation techniques should not present detection problems, according to researchers from Carnegie Mellon and Stanford universities in the US.

Working with virtualisation technology vendors VMware and XenSource, the researchers produced a study called Compatibility is not transparency: VMM detection myths and realities. In the study the researchers claimed that rootkits could not use hypervisor technology to remain undetected on a system.

"No matter how minimal the hostile VMM [virtual machine monitor] is, it must consume physical resources, perturb timings and take measures to protect itself from the guest, leaving it no less susceptible to detection than other VMMs," said the research paper.

Hostile hypervisors create anomalies in the infected system that enable detection, according to the researchers, who said that hypervisors can be detected through logical discrepancies between the interfaces of real and virtual hardware.

Read this

Comment
Comment: The right application of virtualisation

Server virtualisation has its benefits but it's at the application level where the technology can really make a real difference, says DataSynapse's Peter Lee

Read more +

"Most current hypervisor detection methods exploit differences in the virtual CPU interface of VMMs that violate x86 architecture," said the study.

There are also differences between virtual and actual hardware configurations such as chipsets, according to the researchers. And resource discrepancies give the game away, as VMMs consume CPU cycles and physical memory, and have a cache footprint that can be detected.

Malware researcher Joanna Rutkowska claimed last year to have developed a hypervisor rootkit called "Blue Pill" that would remain undetected on a system. Her claims were disputed by researchers from Matasano Security, Root Labs and Symantec.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Application Delivery Solutions Architect Pre-sales Vmware VDI Citrix

Application Delivery / Desktop Virtualisation (VDI) Solutions Architect Pre-sales Consultant - Vmware, VDI, Citrix,(XenDesktop, XenApp and XenServer) ...

Systems Engineer / Technical Engineer VMWare ESX Server / Win2003 - Abingdon, Oxfordshire

Team player with exceptional interpersonal and communication skills - Experience with virtualisation (VMWare ESX Server), MS Active Directory or ...

3rd Line Support Specialist

One of the tasks is taking the servers from a physical state to a virtual environment, so applicants must have good Exchange 2003 knowledge and ...

Sentry Posts Blog

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Google sponsors open source security p...

Google has announced it is to sponsor oCERT, an open source computer emergency response team. In a blog post on Monday, Google security engineer Will Drewry said that one of the... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation