{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/34375"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/34375","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Lightweight and purpose built hypervisor for malware analysis","abstract":"Malicious software is rampant on the Internet and costs billions of dollars each year. Safe and thorough analysis of malware is key to protecting vulnerable systems and cleaning those that have already been infected. Most current state-of-the-art analysis platforms run alongside the malware, increasing their detectability. This reduces the value of analysis because some malware is known to behave differently when being analyzed. Virtualization offers a compelling platform for malware analysis, with strong isolation and the ability to save and restore guest state. Commodity virtual machine monitors (VMMs), however, are not designed for malware analysis. Due to their complexity, they often fail to provide transparency and even expose vulnerabilities which could be exploited by the malware running inside guest system. We design and implement a lightweight VMM (namely MAVMM) that is created specially for one job: malware analysis. MAVMM does not implement unnecessary virtualization features commonly found in general purpose hypervisors, including virtual device emulation. We take advantage of hardware virtualization support to make MAVMM more simple, secure and transparent. In this thesis, we describe the design and implementation of MAVMM, and the features that we can extract from programs running inside the guest OS. We evaluate our platform in three aspects: functionality, detectability and performance. We show that our system can extract useful information from malicious software, and that it is not susceptible to known virtualization detection techniques.","abstract_html":"Malicious software is rampant on the Internet and costs billions of dollars each year. Safe and thorough analysis of malware is key to protecting vulnerable systems and cleaning those that have already been infected. Most current state-of-the-art analysis platforms run alongside the malware, increasing their detectability. This reduces the value of analysis because some malware is known to behave differently when being analyzed. Virtualization offers a compelling platform for malware analysis, with strong isolation and the ability to save and restore guest state. Commodity virtual machine monitors (VMMs), however, are not designed for malware analysis. Due to their complexity, they often fail to provide transparency and even expose vulnerabilities which could be exploited by the malware running inside guest system. We design and implement a lightweight VMM (namely MAVMM) that is created specially for one job: malware analysis. MAVMM does not implement unnecessary virtualization features commonly found in general purpose hypervisors, including virtual device emulation. We take advantage of hardware virtualization support to make MAVMM more simple, secure and transparent. In this thesis, we describe the design and implementation of MAVMM, and the features that we can extract from programs running inside the guest OS. We evaluate our platform in three aspects: functionality, detectability and performance. We show that our system can extract useful information from malicious software, and that it is not susceptible to known virtualization detection techniques.","abstract_has_math":false,"creators":["Nguyen, Anh"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["King, Samuel T."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2012,"date_issued":"2012-09-18T21:13:58Z","date_published":"2012-09-18T21:13:58Z","updated_at":"2026-07-22T22:25:31Z","subjects":["hypervisor","virtual machine monitors (VMM)","small","specialized","malware","analysis"],"languages":["en"],"rights":["Copyright 2012 Anh M. Nguyen"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/34375","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["King, Samuel T."]},{"key":"dc:creator","label":"Author","values":["Nguyen, Anh"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2012-09-18T21:13:58Z","2012-08"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["hypervisor","virtual machine monitors (VMM)","small","specialized","malware","analysis"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2012 Anh M. Nguyen"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/34375"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Malicious software is rampant on the Internet and costs billions of dollars each year. Safe and thorough analysis of malware is key to protecting vulnerable systems and cleaning those that have already been infected. Most current state-of-the-art analysis platforms run alongside the malware, increasing their detectability. This reduces the value of analysis because some malware is known to behave differently when being analyzed. Virtualization offers a compelling platform for malware analysis, with strong isolation and the ability to save and restore guest state. Commodity virtual machine monitors (VMMs), however, are not designed for malware analysis. Due to their complexity, they often fail to provide transparency and even expose vulnerabilities which could be exploited by the malware running inside guest system. We design and implement a lightweight VMM (namely MAVMM) that is created specially for one job: malware analysis. MAVMM does not implement unnecessary virtualization features commonly found in general purpose hypervisors, including virtual device emulation. We take advantage of hardware virtualization support to make MAVMM more simple, secure and transparent. In this thesis, we describe the design and implementation of MAVMM, and the features that we can extract from programs running inside the guest OS. We evaluate our platform in three aspects: functionality, detectability and performance. We show that our system can extract useful information from malicious software, and that it is not susceptible to known virtualization detection techniques.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2012-07-16T13:48:38Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Nguyen_Anh.pdf: 234813 bytes, checksum: 79ed2cad9eefbb5ac29c39dd91d588b4 (MD5)","Made available in DSpace on 2012-09-18T21:13:58Z (GMT). No. of bitstreams: 2 Nguyen_Anh.pdf: 234813 bytes, checksum: 79ed2cad9eefbb5ac29c39dd91d588b4 (MD5) license.txt: 4060 bytes, checksum: 4fceeda70758b3f28dcdf42ca5dcbe95 (MD5)"]},{"key":"dc:title","label":"Title","values":["Lightweight and purpose built hypervisor for malware analysis"]}]}],"canonical_facts":{"dc:contributor":["King, Samuel T."],"dc:creator":["Nguyen, Anh"],"dc:date":["2012-09-18T21:13:58Z","2012-08"],"dc:description":["Malicious software is rampant on the Internet and costs billions of dollars each year. Safe and thorough analysis of malware is key to protecting vulnerable systems and cleaning those that have already been infected. Most current state-of-the-art analysis platforms run alongside the malware, increasing their detectability. This reduces the value of analysis because some malware is known to behave differently when being analyzed. Virtualization offers a compelling platform for malware analysis, with strong isolation and the ability to save and restore guest state. Commodity virtual machine monitors (VMMs), however, are not designed for malware analysis. Due to their complexity, they often fail to provide transparency and even expose vulnerabilities which could be exploited by the malware running inside guest system. We design and implement a lightweight VMM (namely MAVMM) that is created specially for one job: malware analysis. MAVMM does not implement unnecessary virtualization features commonly found in general purpose hypervisors, including virtual device emulation. We take advantage of hardware virtualization support to make MAVMM more simple, secure and transparent. In this thesis, we describe the design and implementation of MAVMM, and the features that we can extract from programs running inside the guest OS. We evaluate our platform in three aspects: functionality, detectability and performance. We show that our system can extract useful information from malicious software, and that it is not susceptible to known virtualization detection techniques.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2012-07-16T13:48:38Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Nguyen_Anh.pdf: 234813 bytes, checksum: 79ed2cad9eefbb5ac29c39dd91d588b4 (MD5)","Made available in DSpace on 2012-09-18T21:13:58Z (GMT). No. of bitstreams: 2 Nguyen_Anh.pdf: 234813 bytes, checksum: 79ed2cad9eefbb5ac29c39dd91d588b4 (MD5) license.txt: 4060 bytes, checksum: 4fceeda70758b3f28dcdf42ca5dcbe95 (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/34375"],"dc:language":["en"],"dc:rights":["Copyright 2012 Anh M. Nguyen"],"dc:subject":["hypervisor","virtual machine monitors (VMM)","small","specialized","malware","analysis"],"dc:title":["Lightweight and purpose built hypervisor for malware analysis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:31Z"}