kirancodes.me
To Proof Maintenance & Beyond!

QEMU-based framework for non-intrusive virtual machine instrumentation and introspection

Pavel Dovgalyuk, Natalia Fursova, Ivan Vasiliev, Vladimir Makarov

Abstract

This paper presents the framework based on the emulator QEMU. Our framework provides set of multi-platform analysis tools for the virtual machines and mechanism for creating instrumentation and analysis tools. Our framework is based on a lightweight approach to dynamic analysis of binary code executed in virtual machines. This approach is non-intrusive and provides system-wide analysis capabilities. It does not require loading any guest agents and source code of the OS. Therefore it may be applied to ROM-based guest systems and enables using of record/replay of the system execution. We use application binary interface (ABI) of the platform to be analyzed for creating introspection tools. These tools recover the part of kernel-level information related to the system calls executed on the guest machine.

BibTeX
@inproceedings{Dovgalyuk-al:FSE17,
  author    = {Pavel Dovgalyuk and
               Natalia Fursova and
               Ivan Vasiliev and
               Vladimir Makarov},
  title     = {{QEMU-based} framework for non-intrusive virtual machine instrumentation and introspection},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {944--948},
  publisher = {{ACM}},
  year      = {2017},
}

Related papers