2018 Annual IEEE International Systems Conference (SysCon) 2018
DOI: 10.1109/syscon.2018.8369612
|View full text |Cite
|
Sign up to set email alerts
|

VM processes state detection by hypervisor tracing

Abstract: The diagnosis of performance issues in cloud environments is a challenging problem, due to the different levels of virtualization, the diversity of applications and their interactions on the same physical host. Moreover, because of privacy, security, ease of deployment and execution overhead, an agent-less method, which limits its data collection to the physical host level, is often the only acceptable solution.In this paper, a precise host-based method, to recover wait state for the processes inside a given V… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1

Citation Types

0
2
0

Year Published

2018
2018
2022
2022

Publication Types

Select...
2
2

Relationship

0
4

Authors

Journals

citations
Cited by 4 publications
(2 citation statements)
references
References 10 publications
(6 reference statements)
0
2
0
Order By: Relevance
“…Traditional malware monitoring tools are installed in the physical host, they trust in the integrity of the host, however, they are vulnerable to being infected by malware and delivering erroneous results about monitoring [10]. The approach proposed in this paper is based on Virtual Machine Introspection (VMI) [11] technique to obtain the memory image of a Virtual Machine (VM), from outside, in this case, with the help of the VirtualBox API [12], analyze its running processes, threads, network connections, and open files with the use of the Volatility Framework [13] and finally, report this information in a monitoring register.…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation
“…Traditional malware monitoring tools are installed in the physical host, they trust in the integrity of the host, however, they are vulnerable to being infected by malware and delivering erroneous results about monitoring [10]. The approach proposed in this paper is based on Virtual Machine Introspection (VMI) [11] technique to obtain the memory image of a Virtual Machine (VM), from outside, in this case, with the help of the VirtualBox API [12], analyze its running processes, threads, network connections, and open files with the use of the Volatility Framework [13] and finally, report this information in a monitoring register.…”
Section: Introductionmentioning
confidence: 99%
“…Virtual Machine Introspection is a technique to analyze the memory of a given VM to detect its internal activities from outside over the Virtual Machine Monitor layer [10], [11]. Such activities are related with memory, disk, CPU registers, network connections and available kernel symbols of the VM [15,16].…”
Section: Virtual Machine Introspectionmentioning
confidence: 99%