RandCompile: Removing Forensic Gadgets from the Linux Kernel to Combat its Analysis
Fabian Franzen, Andreas Chris Wilhelmer, Jens Großklags · Annual Computer Security Applications Conference · 2023
Recently proposed tools such as LogicMem, Katana, and AutoProfile enable a fine-grained inspection of the operating system’s memory. They provide insights that were previously only available for Linux machines specifically instrumented for cooperation with virtual machine introspection frameworks. An overly controlling cloud operator can now regularly deep-inspect VMs under their control.