• Cite Icon22
  • https://doi.org/10.1145/2517326.2451534Copy DOI Icon

EXTERIOR

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

This paper presents EXTERIOR, a dual-VM architecture based external shell that can be used for trusted, timely out-of-VM management of guest-OS such as introspection, configuration, and recovery. Inspired by recent advances in virtual machine introspection (VMI), EXTERIOR leverages an isolated, secure virtual machine (SVM) to introspect the kernel state of a guest virtual machine (GVM). However, it goes far beyond the read-only capability of the traditional VMI, and can perform automatic, fine-grained guest-OS writable operations. The key idea of EXTERIOR is to use a dual-VM architecture in which a SVM runs a kernel identical to that of the GVM to create the necessary environment for a running process (e.g., rmmod, kill), and dynamically and transparently redirect and update the memory state at the VMM layer from SVM to GVM, thereby achieving the same effect in terms of kernel state updates of running the same trusted in-VM program inside the shell of GVM. A proof-of-concept EXTERIOR has been implemented. The experimental results show that EXTERIOR can be used for a timely administration of guest-OS, including introspection and (re)configuration of the guest-OS state and timely response of kernel malware intrusions, without any user account in the guest-OS.

Similar Papers
  • Conference Article
  • Citations17

Dynamic Memory Pressure Aware Ballooning

  • Oct 05, 2015
  • Jinchun Kim +3
  • Research Article
  • Citations2

Efficient and Fine-Grained VMM-Level Packet Filtering for Self-Protection

  • Apr 01, 2014
  • International Journal of Adaptive, Resilient and Autonomic Systems
  • Kenichi Kourai +2
  • Conference Article
  • Citations12

Efficient VM Introspection in KVM and Performance Comparison with Xen

  • Nov 01, 2014
  • Kenichi Kourai +1
  • Conference Article
  • Citations3

VMBeam: Zero-Copy Migration of Virtual Machines for Virtual IaaS Clouds

  • Sep 01, 2016
  • Kenichi Kourai +1
  • Conference Article
  • Citations7

Performance comparison of two virtual machine scenarios using an HPC application

  • Mar 31, 2009
  • Anand Tikotekar +6
  • PDF
  • Conference Article
  • Citations13

RapidVMI: Fast and multi-core aware active virtual machine introspection

  • Aug 17, 2021
  • Thomas Dangl +2
  • Conference Article
  • Citations10

Execution Time Measurement of Virtual Machine Volatile Artifacts Analyzers

  • Dec 01, 2015
  • M.A Ajay Kumara +1
  • Conference Article
  • Citations50

Virtual Machine Introspection: Techniques and Applications

  • Jun 18, 2015
  • Yacine Hebbal +2
  • Conference Article
  • Citations11

Surreptitious Deployment and Execution of Kernel Agents in Windows Guests

  • May 01, 2012
  • Tzi-Cker Chiueh +2
  • Conference Article
  • Citations142

XenLoop

  • Jun 23, 2008
  • Jian Wang +2
  • Book Chapter
  • Citations58

Secure and Robust Monitoring of Virtual Machines through Guest-Assisted Introspection

  • Jan 01, 2012
  • Martim Carbone +3
  • Conference Article
  • Citations12

Evolution of digital forensics in virtualization by using virtual machine introspection

  • Apr 04, 2013
  • James Poore +2
  • Research Article
  • Citations20

Monitoring and Attestation of Virtual Machine Security Health in Cloud Computing

  • Sep 01, 2016
  • IEEE Micro
  • Tianwei Zhang +1
  • Conference Article
  • Citations2

Nodeguard: A Virtualized Introspection Security Approach for the Modern Cloud Data Center

  • May 01, 2022
  • Maha Shamseddine +4
  • PDF
  • Research Article
  • Citations6

Task‐Oriented Multilevel Cooperative Access Control Scheme for Environment with Virtualization and IoT

  • Jan 01, 2018
  • Wireless Communications and Mobile Computing
  • Jian Dong +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.