Research on Technology of Process Hiding Based on VMM

Weiliang Kong, Guang-Yu Zeng, Deng-Yuan Zhou · 2015

Kernel-level Rootkit injects malicious code in the system kernel and realizes vicious function by modifying kernel code and data. The emergence of virtualization technology makes Rootkit hide itself and accesses system resources effectively. This paper proposes a kind of Rootkit based on VMM (VMRootkit) which can hide system process and system cannot find it. For realizing it, we firstly puts forward formal model of VMRootkit about cooperative concealment combined with Trojans thought about cooperative concealment, then researches the process switch and data structure of operating system and realized prototype of it, which can monitor system process and realize process depth hiding by modifying data structure related process view. Experiment shows that VMRootkit prototype meets the idea of cooperative concealment, can realize process depth hiding and has better hidden property than kernel-level Rootkit.

Read the paper · More papers on PaperTik