Study highlights flaws in virtual platform security

Virtual-machine-based rootkits could be used to compromise virtual operating systems

Written by Dave Bailey

Researchers at Microsoft and the University of Michigan (UOM) have created virtual-machine-based rootkits (VMBRs) to demonstrate how the security of virtual operating systems could be compromised.

This news may alarm companies using virtualisation to consolidate services onto commodity hardware with higher CPU utilisation rates; or firms using virtualised desktop operating systems to tackle security problems.

The research staff assumed "the perspective of the attacker who is trying to run malicious software (malware) and avoid detection", according to their paper entitled SubVirt: Implementing malware with virtual machines, which has been conditionally accepted for the 2006 IEEE Symposium on Security and Privacy, which will be held in May.

Brian Gammage of analyst company Gartner issued a warning at Intel's Digital Office initiative in October that virtualisation could create new security weaknesses. A VMBR would operate below the virtual operating system, effectively controlling it.

In their paper, the researchers give details of the implementation of two proof-of-concept VMBRs, one aimed at a Linux/ VMWare system, the other at a Windows XP/VirtualPC system. To complement these VMBRs the researchers developed malicious systems including a keystroke sniffer, a phishing web server, and a data probe for finding sensitive data. They also created a countermeasure to foil the "redpill" method for detecting virtual machines.

To detect VMBRs, the researchers suggested the best way is to take control at a lower level than the VMBR. This would mean detection through a low-level security chipset – a method already proposed by processor vendors Intel and AMD – or booting from "sandboxed" media such as CD-ROMs or USB keys.

Tags:

reader comments

related articles

Virtual tape library can back up any systems

The VTL600 has a sustained throughput of 1.8TB/hour 13 Feb 2006

 

Flexible virtual private LAN rolls out across UK

Can run bandwidth intensive applications, voice and data 09 Jan 2006

Report: Reed hires virtual operator to cut costs

Reed Managed Services says its new telecoms contract will save millions of pounds 03 Mar 2006

Servers to host virtual Windows desktops

Vegas show brings host of announcements 24 Oct 2005

ClearCube controls IBM virtual desktop system

IBM's recently announced scheme for running virtual PCs from blade servers gains ClearCube management tools 14 Nov 2005

Microsoft unveils IE8 security upgrades

New filters tackle phishing and cross-site scripting attacks 03 Jul 2008

Check Point puts ForceField around browsers

ZoneAlarm plays in the sandbox 10 Oct 2007

Kaminsky delivers DNS dirt

Researcher explains risks behind flaw 07 Aug 2008

related whitepapers

today's top stories

Why the ‘e’ in e-Crime?

This week the Home Office announced the creation of the new Police Central e-crime Unit (PCeU). The PCeU promises to tackle cyber... 02 Oct 2008

National Identity Fraud Prevention Week

Every Monday seems to mark the beginning of a new awareness drive and this week’s theme has particular importance to small businesses... 06 Oct 2008

Wanted: a viable model for fibre

While other European countries are pressing ahead with fibre rollouts, progress in the UK is being held back as the debate over who will foot the bill drags on, writes Dave Bailey 02 Oct 2008

ITIL tools add lustre to Technicolor helpdesk

Centralising IT support helped to improve the service to 6,000 users in 58 locations at the film processing firm 02 Oct 2008

Computing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit

In our latest podcast, we discuss the hurdles that a national fibre-optic network must overcome, and look at the issues discussed at the recent IT security conference 02 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Who should pay for the rollout of next-generation broadband?

Who should pay for the rollout of next-generation broadband?

A UK high-speed fibre network could cost up to £30bn - who should fund it?

Previous poll results

Latest audio and video articles

Podcast imageAudio

Computing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit

In our latest podcast, we discuss the hurdles that a national fibre-optic network must overcome, and look at the issues discussed at the recent IT security conference 02 Oct 2008

Ethernet cableVideo

Is high-speed Ethernet ready to roll?

What are the prospects for the next generation of the networking technology? 26 Sep 2008

Latest in-depth articles

Basketball player performing a slam dunkFeatures

Agility brings results - innovation in software development

Companies are increasingly moving away from rigid programming methodologies and adopting more agile approaches that aim to deliver small gains in rapid succession 01 Oct 2008

Co-op storeAnalysis

Computing Awards: Innovative project of the year shortlist

As part of our build-up to the Computing Awards for Excellence, which take place at London’s Battersea Park events arena on 5 November, we turn the spotlight on the nominations for Innovative Project of the Year 01 Oct 2008

Advertisement

Primary Navigation