Hier finden Sie wissenschaftliche Publikationen aus den Fraunhofer-Instituten.

A Universal Semantic Bridge for Virtual Machine Introspection

: Schneider, Christian; Pfoh, Jonas; Eckert, Claudia


Jajodia, S.:
Information Systems Security. 7th international conference, ICISS 2011 : Kolkata, India, December 15-19, 2011, Proceedings
Berlin: Springer, 2011 (Lecture Notes in Computer Science 7093)
ISBN: 978-3-642-25559-5 (Print)
ISBN: 978-3-642-25560-1 (Online)
ISBN: 3-642-25559-0
International Conference on Information System Security (ICISS) <7, 2011, Kolkata>
Conference Paper
Fraunhofer AISEC ()

All systems that utilize virtual machine introspection (VMI) need to overcome the disconnect between the low-level state that the hypervisor sees and its semantics within the guest. This problem has become well-known as the semantic gap. In this work, we introduce our tool, InSight, that establishes a semantic connection between the guest and the hypervisor independent of the application at hand. InSight goes above and beyond previous approaches in that it strives to expose all kernel objects to an application with as little human effort as possible. It features a shell interface for interactive inspection as well as a scripting engine for comfortable and safe development of new VMI-based methods. Due to this flexibility, InSight supports a wide variety of VMI applications, such as intrusion detection, forensic analysis, malware analysis, and kernel debugging.