作者: Sebastian Vogl , Fatih Kilic , Christian Schneider , Claudia Eckert
DOI: 10.1007/978-3-642-38631-2_15
关键词: x86 、 Computer science 、 Hypervisor 、 Overhead (computing) 、 Semantic gap 、 Kernel (statistics) 、 Virtual machine 、 Embedded system 、 Operating system 、 Virtualization 、 Storage hypervisor
摘要: In spite of the fact that security applications can greatly benefit from virtualization, hypervisor-based solutions remain sparse. The main cause for this is semantic gap, which makes development cumbersome, error-prone, and time-consuming. paper, we present X-TIER, a framework enables to bridge gap by injecting kernel modules outside into running virtual machine (VM). While previous approaches reading objects memory, X-TIER goes beyond such work allows injected code manipulate guest operating system (OS) state even call functions without sacrificing overall security. We have implemented prototype on x86 architecture supports module injection Windows Linux guests. evaluation our shows only incurs very small performance overhead, leaves no traces within system, provides access all exported OS data structures functions. Consequently, mechanism well-suited creating applications.