Malware vs Virtualization The endless cat and mouse play

aurelien.wail.ly/publications/hip-2013-slides.html

aurelien.wail.ly/publications/hip-2013-slides.html

Plan

Virtualization

Virtualization usages

Bright side

Dark Side

Mainly for testing purposes!

Malware

On the bright side

Malwares may detect virtualized environments

On the bright side

Malwares may detect virtualized environments

blockdiag-modify-behavior.png

On the dark side

Games may detect virtualized environments

On the dark side

Games may detect virtualized environments

blockdiag-cheat.png blockdiag-cheat-vmm.png

Who is leading ?

How to detect Virtualized environments ?

Is it easier to hide or to detect ?

Targeted escape

Sandbox environments have to

Demo Cuckoo

cuckoo-first-dll.png
Cuckoo

Demo Cuckoo