作者: Yangchun Fu , Zhiqiang Lin
DOI: 10.1109/SP.2012.40
关键词:
摘要: It is generally believed to be a tedious, time consuming, and error-prone process develop virtual machine introspection (VMI) tool manually because of the semantic gap. Recent advances in Virtuoso show that we can largely narrow But it still cannot completely automate VMI generation. In this paper, present VMST, an entirely new technique automatically bridge gap generate tools. The key idea that, through system wide instruction monitoring, identify related data redirect these accesses in-guest kernel memory. VMST offers number features capabilities. Particularly, enables inspection program become program. We have tested over 15 commonly used utilities on top 20 different Linux kernels. experimental results our general (largely OS-agnostic), introduces 9.3X overhead average for introspected compared native non-redirected one.