Study highlights flaws in virtual platform security

Virtual-machine-based rootkits could be used to compromise virtual operating systems

Written by Dave Bailey

Researchers at Microsoft and the University of Michigan (UOM) have created virtual-machine-based rootkits (VMBRs) to demonstrate how the security of virtual operating systems could be compromised.

This news may alarm companies using virtualisation to consolidate services onto commodity hardware with higher CPU utilisation rates; or firms using virtualised desktop operating systems to tackle security problems.

The research staff assumed "the perspective of the attacker who is trying to run malicious software (malware) and avoid detection", according to their paper entitled SubVirt: Implementing malware with virtual machines, which has been conditionally accepted for the 2006 IEEE Symposium on Security and Privacy, which will be held in May.

Brian Gammage of analyst company Gartner issued a warning at Intel's Digital Office initiative in October that virtualisation could create new security weaknesses. A VMBR would operate below the virtual operating system, effectively controlling it.

In their paper, the researchers give details of the implementation of two proof-of-concept VMBRs, one aimed at a Linux/ VMWare system, the other at a Windows XP/VirtualPC system. To complement these VMBRs the researchers developed malicious systems including a keystroke sniffer, a phishing web server, and a data probe for finding sensitive data. They also created a countermeasure to foil the "redpill" method for detecting virtual machines.

To detect VMBRs, the researchers suggested the best way is to take control at a lower level than the VMBR. This would mean detection through a low-level security chipset – a method already proposed by processor vendors Intel and AMD – or booting from "sandboxed" media such as CD-ROMs or USB keys.

Tags:

reader comments

related articles

Virtual tape library can back up any systems

The VTL600 has a sustained throughput of 1.8TB/hour 13 Feb 2006

 

Flexible virtual private LAN rolls out across UK

Can run bandwidth intensive applications, voice and data 09 Jan 2006

Report: Reed hires virtual operator to cut costs

Reed Managed Services says its new telecoms contract will save millions of pounds 03 Mar 2006

Servers to host virtual Windows desktops

Vegas show brings host of announcements 24 Oct 2005

ClearCube controls IBM virtual desktop system

IBM's recently announced scheme for running virtual PCs from blade servers gains ClearCube management tools 14 Nov 2005

Microsoft releases Internet Explorer 8

Latest version of the web browser finally available to download 19 Mar 2009

Symantec report shows huge growth in malware

Cyber criminals increasingly targeting consumers' confidential data 14 Apr 2009

EU pledges to protect cyber infrastructure

Better co-operation needed to deal with natural and intentional disruption 30 Mar 2009

related whitepapers

today's top stories

What does Windows 7 mean for Microsoft?

With the sting of Vista still fresh, Redmond has to make next Windows work 10 Jul 2009

A smarter way to use BI

Getting the most from business intelligence systems requires not only careful management on the part of IT leaders, but also the committed involvement of decision-makers across the organisation 08 Jul 2009

The truth behind the Google/Microsoft/NHS rumours

Before Monday 6 July, did you know that Google and Microsoft had services for storing health records? Thanks to an article in... 10 Jul 2009

Quenching a thirst for IT modernisation

A substantial restructure at soft drink supplier Nichols -­ purveyor of Vimto - ­led the company to update its software to Sage 1000 to replace its in-house application. This resulted in the streamlining of the IT department and an opportunity to customise the system 08 Jul 2009

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will Google Chrome OS be a genuine alternative to Windows?

Will Google Chrome OS be a genuine alternative to Windows?

Tell us your views on the new operating system rivalry

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation