Hide metadata

dc.date.accessioned2013-03-12T08:06:53Z
dc.date.available2013-03-12T08:06:53Z
dc.date.issued2007en_US
dc.date.submitted2007-05-02en_US
dc.identifier.citationBergdal, Mads Andre, Sørby, Trond Arne, . Using virtual machines for integrity checking. Masteroppgave, University of Oslo, 2007en_US
dc.identifier.urihttp://hdl.handle.net/10852/9660
dc.description.abstractToday’s arms race between the attackers and defenders of computer systems seems like a never ending story. Traditionally, the battle has been fought outside the computer’s operating system kernel, but in recent years the advent of kernel level malware has moved the battlefield inside the operating system, thus incapacitating many of the before trusted security mechanisms. When this happens the operating system can no longer be trusted, and new kinds of security tools must be developed. This thesis looks at the potential of virtualization as a platform for performing integrity checking of a running operating system’s kernel. In theory, the use of virtualization should make it possible to establish a platform of trust in the system, even when the kernel of a virtualized guest kernel has been subverted. The idea of monitoring an attacked system from a different protection domain than the attacked system is not new. The use of virtualization brings some extra benefits though: High visibility to the monitored system and good protection from outside attackers. Traditional computer surveillance systems have been forced to compromise between these two properties. The reader is in this thesis introduced to the concept of kernel level malware, virtualization techniques and the internals of the Linux kernel. An architecture designed to address some of the problems surrounding the integrity checking of a running kernel, is presented. The details of this architecture is discussed, and a working prototype putting the architecture to the test against a suite of real attacks, is constructed.nor
dc.language.isoengen_US
dc.titleUsing virtual machines for integrity checkingen_US
dc.typeMaster thesisen_US
dc.date.updated2007-06-13en_US
dc.creator.authorBergdal, Mads Andreen_US
dc.creator.authorSørby, Trond Arneen_US
dc.subject.nsiVDP::420en_US
dc.identifier.bibliographiccitationinfo:ofi/fmt:kev:mtx:ctx&ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:dissertation&rft.au=Bergdal, Mads Andre&rft.au=Sørby, Trond Arne&rft.title=Using virtual machines for integrity checking&rft.inst=University of Oslo&rft.date=2007&rft.degree=Masteroppgaveen_US
dc.identifier.urnURN:NBN:no-14916en_US
dc.type.documentMasteroppgaveen_US
dc.identifier.duo58216en_US
dc.contributor.supervisorChunming Rong, Ane Daae Wengen_US
dc.identifier.bibsys070813825en_US
dc.identifier.fulltextFulltext https://www.duo.uio.no/bitstream/handle/10852/9660/1/Bergdal.pdf


Files in this item

Appears in the following Collection

Hide metadata