Ether: Malware Analysis via Hardware Virtualization Extensions

By A. Dinaburg, P. Royal, M. Sharif and W. Lee

Proceedings of the 15th ACM Conference on Computer and Communications Security 2008 (CCS’08)

Ether is a malware analysis framework which leverages hardware virtualization extensions (specifically Intel VT) to remain transparent to malicious software. It supports both fine- (single instruction) and coarse- (system call) granularity tracing. (I’m curious what the performance penalty for the fine-grain tracing is. The authors only say that it’s “significant”.)

Both the GPL’ed source code for Ether and the paper are available for download at http://ether.gtisc.gatech.edu.

Advertisement

Leave a Reply

Please log in using one of these methods to post your comment:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.