Study highlights flaws in virtual platform security

Virtual-machine-based rootkits could be used to compromise virtual operating systems

Written by Dave Bailey

Researchers at Microsoft and the University of Michigan (UOM) have created virtual-machine-based rootkits (VMBRs) to demonstrate how the security of virtual operating systems could be compromised.

This news may alarm companies using virtualisation to consolidate services onto commodity hardware with higher CPU utilisation rates; or firms using virtualised desktop operating systems to tackle security problems.

The research staff assumed "the perspective of the attacker who is trying to run malicious software (malware) and avoid detection", according to their paper entitled SubVirt: Implementing malware with virtual machines, which has been conditionally accepted for the 2006 IEEE Symposium on Security and Privacy, which will be held in May.

Brian Gammage of analyst company Gartner issued a warning at Intel's Digital Office initiative in October that virtualisation could create new security weaknesses. A VMBR would operate below the virtual operating system, effectively controlling it.

In their paper, the researchers give details of the implementation of two proof-of-concept VMBRs, one aimed at a Linux/ VMWare system, the other at a Windows XP/VirtualPC system. To complement these VMBRs the researchers developed malicious systems including a keystroke sniffer, a phishing web server, and a data probe for finding sensitive data. They also created a countermeasure to foil the "redpill" method for detecting virtual machines.

To detect VMBRs, the researchers suggested the best way is to take control at a lower level than the VMBR. This would mean detection through a low-level security chipset – a method already proposed by processor vendors Intel and AMD – or booting from "sandboxed" media such as CD-ROMs or USB keys.

Tags:

reader comments

related articles

Virtual tape library can back up any systems

The VTL600 has a sustained throughput of 1.8TB/hour 13 Feb 2006

 

Flexible virtual private LAN rolls out across UK

Can run bandwidth intensive applications, voice and data 09 Jan 2006

Report: Reed hires virtual operator to cut costs

Reed Managed Services says its new telecoms contract will save millions of pounds 03 Mar 2006

Servers to host virtual Windows desktops

Vegas show brings host of announcements 24 Oct 2005

ClearCube controls IBM virtual desktop system

IBM's recently announced scheme for running virtual PCs from blade servers gains ClearCube management tools 14 Nov 2005

Microsoft unveils IE8 security upgrades

New filters tackle phishing and cross-site scripting attacks 03 Jul 2008

Kaminsky delivers DNS dirt

Researcher explains risks behind flaw 07 Aug 2008

related whitepapers

today's top stories

Coding moves with the times

We examine how software development has evolved to better serve the changing needs of business, and speaks to IT leaders who are delivering significant benefits to their organisations by using the latest programming methods 15 Oct 2008

Agile framework simplifies offshore development

Case study: Getronics business application services 15 Oct 2008

Computing launches all-new IT jobs site

Updated Computingcareers.co.uk provides enhanced feature for jobseekers 14 Oct 2008

Q&A: BT Business head of SaaS, Chris Lindsay

BT's head of software-as-a-service explains the benefits of the on-demand delivery model and how the current economic downturn could force firms to re-evaluate how they buy software 14 Oct 2008

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Are you worried about your job prospects in IT over the next 12 months?

Are you worried about your job prospects in IT over the next 12 months?

Will the economic crisis affect your job prospects?

Previous poll results

Latest audio and video articles

Remote workerVideo

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Latest in-depth articles

Features

Enter the dragons' den

Getting an innovative IT product off the ground takes cash, commitment and a lot of patience 15 Oct 2008

TimepieceFeatures

Coding moves with the times

We examine how software development has evolved to better serve the changing needs of business, and speaks to IT leaders who are delivering significant benefits to their organisations by using the latest programming methods 15 Oct 2008

Advertisement

Primary Navigation