Detecting Hidden Process with Hardware-Assisted Virtual Machine Monitor

温研,赵金晶,王怀民
DOI: https://doi.org/10.3969/j.issn.1001-3695.2008.11.078
2008-01-01
Abstract:With more and more PC users were accustomed to download and execute programs from Internet,stealth malware had become a major threat to the PC computers.Process hiding was a powerful stealth technique commonly used by stealth malware to evade detection by computer users and anti-malware scanners.This paper proposed a new approach called Libra for detect hidden processes implicitly.Libra implemented a novel lightweight hardware-assisted VMM to obtain the true process list(TPL) from deep within the system.Compared to existing VMM-based approaches,Libra provides two unique advantages: dynamic OS migration and implicit introspection of TPL.The functionality evaluation shows the completeness and effectiveness of Libra.
What problem does this paper attempt to address?