Inside Out: A Paradigm Shift in VM Introspection
Dufy Teguia, Louis Duval, Teo Pisenti, Kahina Lazri, Daniel Hagimont, Thomas Pasquier, Renaud Lachaize, Alain Tchana
Abstract
We present GOODKIT, a new framework for live virtual machine introspection (LVMI) designed for performance, scalability, and safe integration in modern cloud environments. Unlike existing approaches—such as LibVMI—which rely on heavy VM pausing, GOODKIT executes observers as lightweight VMs colocated with the VMM, enabling nativespeed access to the target state while preserving strong isolation. GOODKIT introduces fine-grained, lock-aware memory–coherence mechanisms, a configurable probing subsystem for I/O and kernel-level events, and a mutualization layer that allows multiple observers to operate concurrently without degrading target performance. Across 21 real world use cases, including rootkit detection, ransomware monitoring, and scheduler introspection, GOODKIT delivers high performance (compared to LibVMI), strong isolation, and broad applicability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3459517d-4657-4fa9-b0bb-ede1f0e04f8eBuilds on9
- Firecracker: Lightweight Virtualization for Serverless ApplicationsAlexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori et al.NSDI 2020 · 197 citations
- Seeing Through The Same Lens: Introspecting Guest Address Space At Native SpeedSiqi Zhao, Xuhua Ding, Wen Xu, Dawu GuUSENIX Security 2017 · 18 citations
- Efficient Memory Overcommitment for I/O Passthrough Enabled VMs via Fine-grained Page Meta-data ManagementYaohui Wang, Ben Luo, Yibin ShenUSENIX ATC 2023 · 18 citations
- Security and Performance in the Delegated User-level VirtualizationJiahao Chen, Dingji Li, Zeyu Mi, Yuxuan Liu et al.OSDI 2023 · 10 citations
- 00SEVen - Re-enabling Virtual Machine Forensics: Introspecting Confidential VMs Using Privileged in-VM AgentsFabian Schwarz, Christian RossowUSENIX Security 2024 · 10 citations
Related papers
- BlueGuard: Accelerated Host and Guest Introspection Using DPUsMeni Orenbach, Rami Ailabouni, Nael Masalha, Thanh Nguyen et al.USENIX Security 2025
- PIkit: A New Kernel-Independent Processor-Interconnect RootkitWonJun Song, Hyunwoo Choi, Junhong Kim, Eunsoo Kim et al.USENIX Security 2016 · 13 citations
- Virtuoso: Enabling Fast and Accurate Virtual Memory Research via an Imitation-based Operating System Simulation MethodologyKonstantinos Kanellopoulos, Konstantinos Sgouras, F. Nisa Bostanci, Andreas Kosmas Kakolyris et al.ASPLOS 2025 · 8 citations
- Remote Direct Memory IntrospectionHongyi Liu, Jiarong Xing, Yibo Huang, Danyang Zhuo et al.USENIX Security 2023
- K-Miner: Uncovering Memory Corruption in LinuxDavid Gens, Simon Schmitt, Lucas Davi, Ahmad-Reza SadeghiNDSS 2018 · 58 citations
