2010
DOI: 10.1007/978-3-642-14215-4_3
|View full text |Cite
|
Sign up to set email alerts
|

dAnubis – Dynamic Device Driver Analysis Based on Virtual Machine Introspection

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
12
0
1

Year Published

2011
2011
2023
2023

Publication Types

Select...
3
3
2

Relationship

1
7

Authors

Journals

citations
Cited by 20 publications
(14 citation statements)
references
References 16 publications
0
12
0
1
Order By: Relevance
“…The Anubis driver reports to a usermode application, which communicates with the analysis component over a virtual network. The Anubis extension dAnubis [23] patches the kernel functions that load kernelmode modules. The patched functions then notify dAnubis when kernel-mode malware is loaded.…”
Section: Inside-vs Outside-the-guest Vmimentioning
confidence: 99%
See 2 more Smart Citations
“…The Anubis driver reports to a usermode application, which communicates with the analysis component over a virtual network. The Anubis extension dAnubis [23] patches the kernel functions that load kernelmode modules. The patched functions then notify dAnubis when kernel-mode malware is loaded.…”
Section: Inside-vs Outside-the-guest Vmimentioning
confidence: 99%
“…An example kernel-only analysis is the Anubis extension dAnubis [23]. It is notified whenever malware is loaded into kernel memory.…”
Section: Scope: Single-domain Vs Whole-systemmentioning
confidence: 99%
See 1 more Smart Citation
“…Neugschwandtner et al propose dAnubis [13], which dynamically analyzes malicious MS Windows device drivers. It includes integrity checking of drivers by placing them under supervision.…”
Section: Related Workmentioning
confidence: 99%
“…dAnubis [14] is the technique suggested for VM introspection from outside of it. This method is the successor of Anubis and exclusively monitors Windows device drivers and kernel behaviour.…”
Section: I/o Introspectionmentioning
confidence: 99%