Dynamic malware analysis using IntroVirt: a modified hypervisor-based system

Joshua S. White, Stephen R. Pape, Adam T. Meily, Richard M. Gloo · Proceedings of SPIE, the International Society for Optical Engineering/Proceedings of SPIE · 2013

In this paper, we present a system for Dynamic Malware Analysis which incorporates the use of IntroVirt™. IntroVirt is an introspective hypervisor architecture and infrastructure that supports advanced analysis techniques for stealth-malwareanalysis. This system allows for complete guest monitoring and interaction, including the manipulation and blocking of system calls. IntroVirt is capable of bypassing virtual machine detection capabilities of even the most sophisticated malware, by spoofing returns to system call responses. Additional fuzzing capabilities can be employed to detect both malware vulnerabilities and polymorphism.

Read the paper · More papers on PaperTik