RandCompile: Removing Forensic Gadgets from the Linux Kernel to Combat its Analysis

Fabian Franzen, Andreas Chris Wilhelmer, Jens Großklags · Annual Computer Security Applications Conference · 2023

Recently proposed tools such as LogicMem, Katana, and AutoProfile enable a fine-grained inspection of the operating system’s memory. They provide insights that were previously only available for Linux machines specifically instrumented for cooperation with virtual machine introspection frameworks. An overly controlling cloud operator can now regularly deep-inspect VMs under their control.

Read the paper · More papers on PaperTik