Virtual Machine Introspection and Hypervisor Introspection
Preeti Mishra, Emmanuel S. Pilli, Rahul Joshi · 2021
The traditional host-based intrusion detection approaches can be deployed inside the Virtual Machine (VM) and can be easily evaded by advanced malware or rootkits. The advanced malware can evade the analysis system which is running inside the monitored VM due to sharing the same memory region, allocated to VM. Moreover, traditional network-based IDSes can be deployed at the Cloud servers or gateway points in Cloud network. These IDSes have less visibility of the monitoring VM environment and are good in detecting network-level attacks. However, they are less efficient in detecting VM-specific malware threats. In this chapter, a taxonomy of Virtual Machine Introspection (VMI) and Hypervisor Introspection (HVI) is provided along with a detailed comprehensive summary of various advanced introspection-based approaches. These approaches are capable of detecting the VM and VMM specific attacks such as side-channel attacks, VMM-hyperjacking, VM Escape etc. This chapter will be very useful for the readers in gaining deeper understanding on virtualization specific security approaches.