Paper
28 May 2013 Dynamic malware analysis using IntroVirt: a modified hypervisor-based system
Joshua S. White, Stephen R. Pape, Adam T. Meily, Richard M. Gloo
Author Affiliations +
Abstract
In this paper, we present a system for Dynamic Malware Analysis which incorporates the use of IntroVirt™. IntroVirt is an introspective hypervisor architecture and infrastructure that supports advanced analysis techniques for stealth-malwareanalysis. This system allows for complete guest monitoring and interaction, including the manipulation and blocking of system calls. IntroVirt is capable of bypassing virtual machine detection capabilities of even the most sophisticated malware, by spoofing returns to system call responses. Additional fuzzing capabilities can be employed to detect both malware vulnerabilities and polymorphism.
© (2013) COPYRIGHT Society of Photo-Optical Instrumentation Engineers (SPIE). Downloading of the abstract is permitted for personal use only.
Joshua S. White, Stephen R. Pape, Adam T. Meily, and Richard M. Gloo "Dynamic malware analysis using IntroVirt: a modified hypervisor-based system", Proc. SPIE 8757, Cyber Sensing 2013, 87570D (28 May 2013); https://doi.org/10.1117/12.2015545
Lens.org Logo
CITATIONS
Cited by 5 scholarly publications.
Advertisement
Advertisement
RIGHTS & PERMISSIONS
Get copyright permission  Get copyright permission on Copyright Marketplace
KEYWORDS
Operating systems

Binary data

Analytical research

Computing systems

Reverse engineering

Artificial intelligence

Computer intrusion detection

Back to Top