Thursday, January 25, 2007 8:30 AM cmosby

Symantec Security Response Weblog: Attacks on Virtual Machines

Attacks on Virtual Machines

At AVAR 2006, I presented a paper which discussed ways in which virtual machines are vulnerable to detection and, in some cases, forced hangs or crashes.

The paper briefly discusses the two major types of virtual machines ("hardware-bound" and "pure software") and the two hardware-bound subtypes ("hardware-assisted" and "reduced-privilege guest"). The focus of the paper is the different ways in which various virtual machines can be detected. There are detections for VMware, VirtualPC, Parallels, Bochs, Hydra (though the published methods have since been fixed), QEMU, Atlantis and Sandbox, along with lots of source code.

The slides from the talk are also available, but without the commentary, they're not quite as interesting. The paper and slides are available from here.

Symantec Security Response Weblog: Attacks on Virtual Machines.

Filed under: ,

Comments

No Comments