{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/78671"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/78671","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Hypervisor introspection: a technique for evading passive virtual machine monitoring","abstract":"Virtualization technology has enabled powerful security monitoring techniques, such as virtual machine introspection (VMI). These monitoring techniques, however, rely on the assumed isolation of virtualized environments from the hypervisor. We show that there are still some events that can be observed that break this isolation. External observers can discern when virtual machines are suspended due to hypervisor activity, and can use this information to mount advanced attacks that go undetected by VMI monitoring systems. We demonstrate some example attacks against realistic monitors using our technique, and discuss existing and potential defenses against these kinds of attacks.","abstract_html":"Virtualization technology has enabled powerful security monitoring techniques, such as virtual machine introspection (VMI). These monitoring techniques, however, rely on the assumed isolation of virtualized environments from the hypervisor. We show that there are still some events that can be observed that break this isolation. External observers can discern when virtual machines are suspended due to hypervisor activity, and can use this information to mount advanced attacks that go undetected by VMI monitoring systems. We demonstrate some example attacks against realistic monitors using our technique, and discuss existing and potential defenses against these kinds of attacks.","abstract_has_math":false,"creators":["Wang, Gary L"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2015,"date_issued":"2015-04-27","date_published":"2015-04-27","updated_at":"2026-07-22T22:26:12Z","subjects":["security","virtual machine introspection (VMI)","side-channel","cloud"],"languages":["en"],"rights":["Copyright 2015 Gary Wang"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/78671","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Wang, Gary L"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2015-04-27","2015-5","2015-07-22T22:33:55Z","2017-07-23T09:15:19Z","2015-05"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["security","virtual machine introspection (VMI)","side-channel","cloud"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2015 Gary Wang"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/78671"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Virtualization technology has enabled powerful security monitoring techniques, such as virtual machine introspection (VMI). These monitoring techniques, however, rely on the assumed isolation of virtualized environments from the hypervisor. We show that there are still some events that can be observed that break this isolation. External observers can discern when virtual machines are suspended due to hypervisor activity, and can use this information to mount advanced attacks that go undetected by VMI monitoring systems. We demonstrate some example attacks against realistic monitors using our technique, and discuss existing and potential defenses against these kinds of attacks.","Submission published under a 24 month embargo labeled 'U of I only', the embargo will last until 2017-05-01","The student, Gary Wang, accepted the attached license on 2015-04-24 at 14:37.","The student, Gary Wang, submitted this Thesis for approval on 2015-04-24 at 14:48.","This Thesis was approved for publication on 2015-04-27 at 17:02.","DSpace SAF Submission Ingestion Package generated from Vireo submission #8096 on 2015-07-22 at 14:18:52","Made available in DSpace on 2015-07-22T22:33:55Z (GMT). No. of bitstreams: 2 WANG-THESIS-2015.pdf: 1084800 bytes, checksum: ef73b7149b1241268e3eca20b5ea70b1 (MD5) LICENSE.txt: 4206 bytes, checksum: aa16f144037dc9dafdda360d1f08fa11 (MD5) Previous issue date: 2015-04-27","Embargo set by: Seth Robbins for item 79912 Lift date: 2017-07-22T22:34:16Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 79912 on 2017-07-23T09:15:19Z."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Hypervisor introspection: a technique for evading passive virtual machine monitoring"]}]}],"canonical_facts":{"dc:creator":["Wang, Gary L"],"dc:date":["2015-04-27","2015-5","2015-07-22T22:33:55Z","2017-07-23T09:15:19Z","2015-05"],"dc:description":["Virtualization technology has enabled powerful security monitoring techniques, such as virtual machine introspection (VMI). These monitoring techniques, however, rely on the assumed isolation of virtualized environments from the hypervisor. We show that there are still some events that can be observed that break this isolation. External observers can discern when virtual machines are suspended due to hypervisor activity, and can use this information to mount advanced attacks that go undetected by VMI monitoring systems. We demonstrate some example attacks against realistic monitors using our technique, and discuss existing and potential defenses against these kinds of attacks.","Submission published under a 24 month embargo labeled 'U of I only', the embargo will last until 2017-05-01","The student, Gary Wang, accepted the attached license on 2015-04-24 at 14:37.","The student, Gary Wang, submitted this Thesis for approval on 2015-04-24 at 14:48.","This Thesis was approved for publication on 2015-04-27 at 17:02.","DSpace SAF Submission Ingestion Package generated from Vireo submission #8096 on 2015-07-22 at 14:18:52","Made available in DSpace on 2015-07-22T22:33:55Z (GMT). No. of bitstreams: 2 WANG-THESIS-2015.pdf: 1084800 bytes, checksum: ef73b7149b1241268e3eca20b5ea70b1 (MD5) LICENSE.txt: 4206 bytes, checksum: aa16f144037dc9dafdda360d1f08fa11 (MD5) Previous issue date: 2015-04-27","Embargo set by: Seth Robbins for item 79912 Lift date: 2017-07-22T22:34:16Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 79912 on 2017-07-23T09:15:19Z."],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/78671"],"dc:language":["en"],"dc:rights":["Copyright 2015 Gary Wang"],"dc:subject":["security","virtual machine introspection (VMI)","side-channel","cloud"],"dc:title":["Hypervisor introspection: a technique for evading passive virtual machine monitoring"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:26:12Z"}