2011
DOI: 10.1007/978-3-642-25141-2_7
|View full text |Cite
|
Sign up to set email alerts
|

Nitro: Hardware-Based System Call Tracing for Virtual Machines

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
45
0

Year Published

2013
2013
2022
2022

Publication Types

Select...
4
1
1

Relationship

0
6

Authors

Journals

citations
Cited by 71 publications
(45 citation statements)
references
References 6 publications
0
45
0
Order By: Relevance
“…In this way, the system call can be successfully re-executed when the handler returned. By reenabling system calls, we also guarantee a more transparent execution environment in contrast to earlier approaches [1], which disable system calls for the entire analysis process. This seems to be a subtle difference, but it can be exceptionally useful against attacks (e.g., [6], [7]) which generate invalid opcodes to detect virtualization or debuggers.…”
Section: B Extending New Blue Pill With Tracing Capabilitiesmentioning
confidence: 99%
See 4 more Smart Citations
“…In this way, the system call can be successfully re-executed when the handler returned. By reenabling system calls, we also guarantee a more transparent execution environment in contrast to earlier approaches [1], which disable system calls for the entire analysis process. This seems to be a subtle difference, but it can be exceptionally useful against attacks (e.g., [6], [7]) which generate invalid opcodes to detect virtualization or debuggers.…”
Section: B Extending New Blue Pill With Tracing Capabilitiesmentioning
confidence: 99%
“…As the #UD exception does not increases the instruction pointer (RIP), we do not have to bother with alignments to re-execute the SYSCALL. In contrast to [1], we enable here the EFER.SCE bit again for higher transparency. However, depending on the chosen transparencygranularity tradeoff, later we disable this bit again.…”
Section: Proposed System Call Tracing Methods For X64mentioning
confidence: 99%
See 3 more Smart Citations