Slashdot Mirror


VM-Based Rootkits Proved Easily Detectable

paleshadows writes "A year and a half has passed since SubVirt, the first VMM (virtual machine monitor) based rootkit, was introduced (PDF), covered in the tech press, and discussed here. Later Joanna Rutkowska made news by claiming she had a VMM-based attack on Vista that was undetectable — a claim that was roundly challenged. Now in this year's HotOS workshop, researchers from Stanford, CMU, VMware, and XenSource have published a paper titled Compatibility Is Not Transparency: VMM Detection Myths and Realities (PDF) showing that VMM-based rootkits are actually easily detectable."

1 of 128 comments (clear)

  1. Once again proves women are incompetent scientists by Anonymous Coward · · Score: -1, Offtopic

    Next let's have a study from Sally Pollyanna about how to drive well.