USENIX Security2017Top-tier venue
Seeing Through The Same Lens: Introspecting Guest Address Space At Native Speed
Siqi Zhao, Xuhua Ding, Wen Xu, Dawu Gu
Abstract
Software-based MMU emulation lies at the heart of outof-VM live memory introspection, an important technique in the cloud setting that applications such as live forensics and intrusion detection depend on. Due to the emulation, the software-based approach is much slower compared to native memory access by the guest VM. The slowness not only results in undetected transient malicious behavior, but also inconsistent memory view with the guest; both undermine the effectiveness of introspection. We propose the immersive execution environment (ImEE) with which the guest memory is accessed at native speed without any emulation. Meanwhile, the address mappings used within the ImEE are ensured to be consistent with the guest throughout the introspection session. We have implemented a prototype of the ImEE on Linux KVM. The experiment results show that ImEE-based introspection enjoys a remarkable speed up, performing several hundred times faster than the legacy method. Hence, this design is especially useful for realtime monitoring, incident response and high-intensity introspection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4c9fc337-c6cb-4baa-8149-b4566c158da4Cited by top-tier papers10
- Hecate: Lifting and Shifting On-Premises Workloads to an Untrusted CloudXinyang Ge, Hsuan-Chi Kuo, Weidong CuiCCS 2022 · 14 citations
- Smile: Secure Memory Introspection for Live EnclaveLei Zhou, Xuhua Ding, Fengwei ZhangS&P 2022 · 13 citations
- 00SEVen - Re-enabling Virtual Machine Forensics: Introspecting Confidential VMs Using Privileged in-VM AgentsFabian Schwarz, Christian RossowUSENIX Security 2024 · 10 citations
- A Novel Dynamic Analysis Infrastructure to Instrument Untrusted Execution Flow Across User-Kernel SpacesJiaqi Hong, Xuhua DingS&P 2021 · 10 citations
- BlueGuard: Accelerated Host and Guest Introspection Using DPUsMeni Orenbach, Rami Ailabouni, Nael Masalha, Thanh Nguyen et al.USENIX Security 2025
Related papers
- Inside Out: A Paradigm Shift in VM IntrospectionDufy Teguia, Louis Duval, Teo Pisenti, Kahina Lazri et al.OSDI 2026
- SKEE: A lightweight Secure Kernel-level Execution Environment for ARMAhmed M. Azab, Kirk Swidowski, Rohan Bhutkar, Jia Ma et al.NDSS 2016 · 105 citations
- Efficient greybox fuzzing of applications in Linux-based IoT devices via enhanced user-mode emulationYaowen Zheng, Yuekang Li, Cen Zhang, Hongsong Zhu et al.ISSTA 2022 · 34 citations
- Forming Faster Firmware FuzzersLukas Seidel, Dominik Christian Maier, Marius MuenchUSENIX Security 2023
- Remote Direct Memory IntrospectionHongyi Liu, Jiarong Xing, Yibo Huang, Danyang Zhuo et al.USENIX Security 2023
