VM Rootkits: The Next Big Threat?

Lab rats at Microsoft Research and the University of Michigan have teamed up to create prototypes for virtual machine-based rootkits that significantly push the envelope for hiding malware and that can maintain control of a target operating system. The proof-of-concept rootkit, called SubVirt, exploits known security flaws and drops a VMM (virtual machine monitor) underneath a Windows or Linux installation. Once the target operating system is hoisted into a virtual machine, the rootkit becomes impossible to detect because its state cannot be accessed by security software running in the target system.

38 Comments

  1. 2006-03-11 9:36 pm
  2. 2006-03-11 9:48 pm
    • 2006-03-11 10:07 pm
  3. 2006-03-11 10:16 pm
  4. 2006-03-11 10:28 pm
  5. 2006-03-11 11:26 pm
  6. 2006-03-12 12:47 am
    • 2006-03-12 2:44 am
      • 2006-03-12 6:29 pm
        • 2006-03-12 6:39 pm
        • 2006-03-12 8:37 pm
  7. 2006-03-12 2:28 am
    • 2006-03-12 7:23 am
  8. 2006-03-12 5:10 am
    • 2006-03-12 12:33 pm
  9. 2006-03-12 1:37 pm
    • 2006-03-12 6:50 pm
  10. 2006-03-12 5:33 pm
    • 2006-03-12 5:41 pm
    • 2006-03-12 6:28 pm
  11. 2006-03-12 7:40 pm
    • 2006-03-12 8:35 pm
      • 2006-03-12 8:51 pm
        • 2006-03-13 2:32 pm
          • 2006-03-13 10:48 pm
          • 2006-03-13 11:25 pm
          • 2006-03-14 2:02 am
          • 2006-03-14 2:13 am
  12. 2006-03-12 8:47 pm
  13. 2006-03-13 5:53 am
  14. 2006-03-13 9:24 am
  15. 2006-03-13 9:54 am
  16. 2006-03-13 3:06 pm
  17. 2006-03-14 1:34 am
  18. 2006-03-14 4:58 am
  19. 2006-03-14 7:31 am
  20. 2006-03-14 11:06 am
  21. 2006-03-14 12:08 pm