Virtual Rootkit Targets OS, Not Virtual Machines
Friday, 17 March 2006 by Michel Roth
In response to an article in eWeek I referenced about a proof-of-concept rootkit that hides itself using virtualization technology, the VMTN Blog has a post up on explaining that this proof-of-concept rootkit targets the target OS, not the Virtual Machines:

First off, it is important to understand that this threat targets the operating system. It is not about vulnerabilities in virtualization. Operating systems running on physical machines are vulnerable to this threat, as the paper shows by targeting Windows XP and Linux systems running directly on an x86 PC.

An interesting implication of the study is that operating systems that are already running in virtual machines are actually less vulnerable. This is because of the performance and correctness challenges of running a virtual machine within a virtual machine, and because a legitimate virtualization layer still runs beneath the rootkit.

In practice today, a virtual machine-based rootkit is not any more powerful than a standard rootkit in hiding itself. There are many straightforward techniques that can be used to detect if an operating system has been moved into a virtual machine.

In the future, when hardware support for virtualization becomes complete enough, techniques for an operating system to verify that it is running in a legitimate virtual machine (or physical machine) will be able to defend against virtual machine-based rootkits. Virtualization software can also detect if a guest operating system has been compromised.


Read it on here.

Related Items:

VM Rootkits: The Next Big Threat? (13 March 2006)
The Virtual PC Guy On Virtual Server 2005 R2 And Hardware Virtualization (2 May 2006)
Double-Take For Virtual Systems (13 February 2006)
Transparent Paravirtualization And The Proposed Virtual Machine Interface (VMI) (10 May 2006)
The Rings Of Power: Intel's VT-x Technology And The Secrets Of Virtualization (16 December 2005)
Official Announcement On Free VMware Server By VMware (6 February 2006)
Hardware Requirements For 64-Bit Guest Operating Systems (11 May 2006)
Microsoft Virtual Server 2005 R2 For Free ! (3 April 2006)
Sysinternals Releases RootkitRevealer (24 February 2005)
Timekeeping And VMware Virtual Machines (27 July 2005)
Comments (0)