6533b7d6fe1ef96bd1266910

RESEARCH PRODUCT

Creating modern blue pills and red pills

Asaf AlgawiMichael KiperbergRoee LeonAmit ReshNezer Zaidenberg

subject

tekninen rikostutkintaforensicsvirtualisointikyberrikollisuusinformation securitytietoturvakyberturvallisuusvirtualizationtietomurtoverkkohyökkäykset

description

The blue pill is a malicious stealthy hypervisor-based rootkit. The red pill is a software package that is designed to detect such blue pills. Since the blue pill was originally proposed there has been an ongoing arms race between developers that try to develop stealthy hypervisors and developers that try to detect such stealthy hypervisors. Furthermore, hardware advances have made several stealth attempts impossible while other advances enable even more stealthy operation. In this paper we describe the current status of detecting stealth hypervisors and methods to counter them. peerReviewed

http://urn.fi/URN:NBN:fi:jyu-202001071039