Matches in SemOpenAlex for { <https://semopenalex.org/work/W2098431065> ?p ?o ?g. }
- W2098431065 abstract "Malicious software is rampant on the Internet and costs billions of dollars each year. Safe and thorough analysis of malware is key to protecting vulnerable systems and cleaning those that have already been infected. Most current state-of-the-art analysis platforms run alongside the malware, increasing their detectability. This reduces the value of analysis because some malware is known to behave differently when being analyzed. Virtualization offers a compelling platform for malware analysis, with strong isolation and the ability to save and restore guest state. Current virtual machine monitors (VMMs), however, are not designed for malware analysis. Due to their complexity, they often fail to provide transparency and even expose vulnerabilities which could be exploited by the malware running inside guest system. We propose a lightweight VMM (namely MAVMM) that is designed specially for a single job: malware analysis. MAVMM does not implement unnecessary virtualization features commonly found in general purpose hypervisors, including virtual device emulation. We take advantage of hardware virtualization support to make MAVMM more simple, secure and transparent. In this paper, we describe the design and implementation of MAVMM, and the features that we can extract from programs running inside the guest OS. We evaluate our platform in three aspects: functionality, detectability and performance. We show that our system can extract useful information from malicious software, and that it is not susceptible to known virtualization detection techniques." @default.
- W2098431065 created "2016-06-24" @default.
- W2098431065 creator A5019673189 @default.
- W2098431065 creator A5023835049 @default.
- W2098431065 creator A5031941449 @default.
- W2098431065 creator A5064193766 @default.
- W2098431065 creator A5071712157 @default.
- W2098431065 creator A5080795334 @default.
- W2098431065 date "2009-12-01" @default.
- W2098431065 modified "2023-10-01" @default.
- W2098431065 title "MAVMM: Lightweight and Purpose Built VMM for Malware Analysis" @default.
- W2098431065 cites W1903377156 @default.
- W2098431065 cites W1968632081 @default.
- W2098431065 cites W2029224396 @default.
- W2098431065 cites W2117882778 @default.
- W2098431065 cites W2119251836 @default.
- W2098431065 cites W2134984199 @default.
- W2098431065 cites W2138830053 @default.
- W2098431065 cites W2140807364 @default.
- W2098431065 cites W2159702664 @default.
- W2098431065 cites W4231945399 @default.
- W2098431065 cites W4243052451 @default.
- W2098431065 cites W4243947286 @default.
- W2098431065 doi "https://doi.org/10.1109/acsac.2009.48" @default.
- W2098431065 hasPublicationYear "2009" @default.
- W2098431065 type Work @default.
- W2098431065 sameAs 2098431065 @default.
- W2098431065 citedByCount "60" @default.
- W2098431065 countsByYear W20984310652012 @default.
- W2098431065 countsByYear W20984310652013 @default.
- W2098431065 countsByYear W20984310652014 @default.
- W2098431065 countsByYear W20984310652015 @default.
- W2098431065 countsByYear W20984310652016 @default.
- W2098431065 countsByYear W20984310652017 @default.
- W2098431065 countsByYear W20984310652018 @default.
- W2098431065 countsByYear W20984310652019 @default.
- W2098431065 countsByYear W20984310652020 @default.
- W2098431065 countsByYear W20984310652021 @default.
- W2098431065 countsByYear W20984310652022 @default.
- W2098431065 countsByYear W20984310652023 @default.
- W2098431065 crossrefType "proceedings-article" @default.
- W2098431065 hasAuthorship W2098431065A5019673189 @default.
- W2098431065 hasAuthorship W2098431065A5023835049 @default.
- W2098431065 hasAuthorship W2098431065A5031941449 @default.
- W2098431065 hasAuthorship W2098431065A5064193766 @default.
- W2098431065 hasAuthorship W2098431065A5071712157 @default.
- W2098431065 hasAuthorship W2098431065A5080795334 @default.
- W2098431065 hasConcept C111919701 @default.
- W2098431065 hasConcept C112904061 @default.
- W2098431065 hasConcept C13062989 @default.
- W2098431065 hasConcept C142355369 @default.
- W2098431065 hasConcept C149635348 @default.
- W2098431065 hasConcept C149810388 @default.
- W2098431065 hasConcept C162324750 @default.
- W2098431065 hasConcept C25344961 @default.
- W2098431065 hasConcept C2775941552 @default.
- W2098431065 hasConcept C2777904410 @default.
- W2098431065 hasConcept C2779395397 @default.
- W2098431065 hasConcept C38652104 @default.
- W2098431065 hasConcept C41008148 @default.
- W2098431065 hasConcept C47878483 @default.
- W2098431065 hasConcept C50522688 @default.
- W2098431065 hasConcept C513985346 @default.
- W2098431065 hasConcept C541664917 @default.
- W2098431065 hasConcept C68793194 @default.
- W2098431065 hasConcept C79974875 @default.
- W2098431065 hasConcept C84525096 @default.
- W2098431065 hasConcept C86803240 @default.
- W2098431065 hasConcept C89423630 @default.
- W2098431065 hasConceptScore W2098431065C111919701 @default.
- W2098431065 hasConceptScore W2098431065C112904061 @default.
- W2098431065 hasConceptScore W2098431065C13062989 @default.
- W2098431065 hasConceptScore W2098431065C142355369 @default.
- W2098431065 hasConceptScore W2098431065C149635348 @default.
- W2098431065 hasConceptScore W2098431065C149810388 @default.
- W2098431065 hasConceptScore W2098431065C162324750 @default.
- W2098431065 hasConceptScore W2098431065C25344961 @default.
- W2098431065 hasConceptScore W2098431065C2775941552 @default.
- W2098431065 hasConceptScore W2098431065C2777904410 @default.
- W2098431065 hasConceptScore W2098431065C2779395397 @default.
- W2098431065 hasConceptScore W2098431065C38652104 @default.
- W2098431065 hasConceptScore W2098431065C41008148 @default.
- W2098431065 hasConceptScore W2098431065C47878483 @default.
- W2098431065 hasConceptScore W2098431065C50522688 @default.
- W2098431065 hasConceptScore W2098431065C513985346 @default.
- W2098431065 hasConceptScore W2098431065C541664917 @default.
- W2098431065 hasConceptScore W2098431065C68793194 @default.
- W2098431065 hasConceptScore W2098431065C79974875 @default.
- W2098431065 hasConceptScore W2098431065C84525096 @default.
- W2098431065 hasConceptScore W2098431065C86803240 @default.
- W2098431065 hasConceptScore W2098431065C89423630 @default.
- W2098431065 hasLocation W20984310651 @default.
- W2098431065 hasOpenAccess W2098431065 @default.
- W2098431065 hasPrimaryLocation W20984310651 @default.
- W2098431065 hasRelatedWork W1160228429 @default.
- W2098431065 hasRelatedWork W1606290493 @default.
- W2098431065 hasRelatedWork W1714149143 @default.
- W2098431065 hasRelatedWork W2050616295 @default.
- W2098431065 hasRelatedWork W2065933154 @default.
- W2098431065 hasRelatedWork W2112715807 @default.