{"id":{"repo_id":"uoit","oai_identifier":"oai:ontariotechu.scholaris.ca:10155/1585"},"canonical_url":"https://search.dev.ndltd.org/etd/uoit/oai:ontariotechu.scholaris.ca:10155/1585","repository":{"repo_id":"uoit","name":"Ontario Institute of Technology","base_url":"https://ontariotechu.scholaris.ca/server/oai/request"},"display":{"title":"Virtual machine detection through Central Processing Unit (CPU) detail anomalies","abstract":"Malware analysts commonly use virtual machines to provide safe environments to study malware. Malware authors in response, include virtual machine detection functions in their malware so it changes its behavior should a virtual machine be detected. It is therefore important for researchers to continuously uncover new virtual machine detection methods that may be exploited by criminals. This thesis explores a method of virtual machine detection that looks for inconsistencies in the following Central Processing Unit (CPU) details: the CPU model, the number of physical cores, the number of logical cores and the cache capacities. Should inconsistencies be detected, a virtual machine is present. We explore our method in scenarios where all CPU cores are assigned to the test virtual machines to determine if inconsistencies exist. In our tests, many of the hypervisors tested possessed inconsistencies that could be used to deduce the presence of a virtual machine.","abstract_html":"Malware analysts commonly use virtual machines to provide safe environments to study malware. Malware authors in response, include virtual machine detection functions in their malware so it changes its behavior should a virtual machine be detected. It is therefore important for researchers to continuously uncover new virtual machine detection methods that may be exploited by criminals. This thesis explores a method of virtual machine detection that looks for inconsistencies in the following Central Processing Unit (CPU) details: the CPU model, the number of physical cores, the number of logical cores and the cache capacities. Should inconsistencies be detected, a virtual machine is present. We explore our method in scenarios where all CPU cores are assigned to the test virtual machines to determine if inconsistencies exist. In our tests, many of the hypervisors tested possessed inconsistencies that could be used to deduce the presence of a virtual machine.","abstract_has_math":false,"creators":["Mettrick, David"],"institution":"University of Ontario Institute of Technology","degree_name":"Master of Science (MSc)","degree_level":null,"degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":["Hung, Patrick"],"committee_chairs":[],"committee_members":[],"year":2022,"date_issued":"2022-12-01","date_published":"2022-12-01","updated_at":"2026-07-24T05:35:24Z","subjects":["Virtualization","Hypervisor","Security","Malware","Virtual machine"],"languages":["en"],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/10155/1585","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Hung, Patrick"]},{"key":"dc:creator","label":"Author","values":["Mettrick, David"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2023-03-13T16:33:15Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2023-03-13T16:33:15Z"]},{"key":"dc:date.issued","label":"Date","values":["2022-12-01"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science (MSc)"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Ontario Institute of Technology"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Virtualization","Hypervisor","Security","Malware","Virtual machine"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10155/1585"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Malware analysts commonly use virtual machines to provide safe environments to study malware. Malware authors in response, include virtual machine detection functions in their malware so it changes its behavior should a virtual machine be detected. It is therefore important for researchers to continuously uncover new virtual machine detection methods that may be exploited by criminals. This thesis explores a method of virtual machine detection that looks for inconsistencies in the following Central Processing Unit (CPU) details: the CPU model, the number of physical cores, the number of logical cores and the cache capacities. Should inconsistencies be detected, a virtual machine is present. We explore our method in scenarios where all CPU cores are assigned to the test virtual machines to determine if inconsistencies exist. In our tests, many of the hypervisors tested possessed inconsistencies that could be used to deduce the presence of a virtual machine."]},{"key":"dc:title","label":"Title","values":["Virtual machine detection through Central Processing Unit (CPU) detail anomalies"]}]}],"canonical_facts":{"dc:contributor.advisor":["Hung, Patrick"],"dc:creator":["Mettrick, David"],"dc:date.accessioned":["2023-03-13T16:33:15Z"],"dc:date.available":["2023-03-13T16:33:15Z"],"dc:date.issued":["2022-12-01"],"dc:description.abstract":["Malware analysts commonly use virtual machines to provide safe environments to study malware. Malware authors in response, include virtual machine detection functions in their malware so it changes its behavior should a virtual machine be detected. It is therefore important for researchers to continuously uncover new virtual machine detection methods that may be exploited by criminals. This thesis explores a method of virtual machine detection that looks for inconsistencies in the following Central Processing Unit (CPU) details: the CPU model, the number of physical cores, the number of logical cores and the cache capacities. Should inconsistencies be detected, a virtual machine is present. We explore our method in scenarios where all CPU cores are assigned to the test virtual machines to determine if inconsistencies exist. In our tests, many of the hypervisors tested possessed inconsistencies that could be used to deduce the presence of a virtual machine."],"dc:identifier.uri":["https://hdl.handle.net/10155/1585"],"dc:language.iso":["en"],"dc:subject":["Virtualization","Hypervisor","Security","Malware","Virtual machine"],"dc:title":["Virtual machine detection through Central Processing Unit (CPU) detail anomalies"],"dc:type":["Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_name":["Master of Science (MSc)"],"thesis:institution_name":["University of Ontario Institute of Technology"]},"updated_at":"2026-07-24T05:35:24Z"}