Controlling the speed of virtual time for malware deactivation

Keisuke Okamura, Yoshihiro Oyama · 2012

We propose a mostly OS-independent, VMM-based method that deactivates malware at the granularity of a process. Specifically, the method slows malware processes extremely by shortening the timer interrupt intervals and modifying the system time value: the amount of time that elapses from the boot. We implemented a VMM based on the method, named HyperSlow, and confirmed that it can slow a particular process considerably.

Read the paper · More papers on PaperTik