Malicious Hypervisor Threat – Phase Two: How to Catch the Hypervisor

No ratings

Presented at Deepsec 2016 by

In our 2014 presentation we proved that the threat of Malicious Hypervisor (MH) is a technical reality. The question is not whether it can be implemented - In our opinion it has been implemented and in use since 2007 – 2008 and, in all likelihood, another instance has been developed around 2009 – 2010- The question is when it will become available for real cyber terrorism attacks. We have not seen such an attack yet. More likely MH has been used to collect important information in silence very effectively. However, we cannot control the underground exploitation of software development and an MH attack may happen any time. As we stressed in our 2014 presentation, there is no effective method to discover MH. So, since we said A, by doing our first MH research, we considered it as our obligation to say B, dedicating the next phase of our research to the development of methods and tools to catch the MH. Our presentation will basically cover our research and the development process, outlining some important ideas and findings and providing results proving that our methods and software work and can reliably be used to discover MH. However, we do not consider it as productive to simply provide the exact information about the research and the development. We want to avoid “copy-cat” processes and would like to encourage security researchers and organizations to conduct independent research and development work using our “milestones”. From our point of view, we achieved our goal – we have the methods and we have a tool utilizing these methods. We have both a demo and production version of the Hypervisor Catcher tool which can discover MH in a computer system with 99.99% reliability and within a very reasonable time frame. We do not think that we will be able to prevent MH attacks if they happen in the near future. However, at least we are now able to identify the silent deployment of such an devastating attacking tool. During the presentation I will briefly introduce the audience to the most important information and conclusions of the research of our Phase 1 (as discussed at DeepSec 2014). We will also discuss our analysis of methods used in the traditional research concerning the “rootkit hypervisor” to catch hypervisor activity. Then we will move on to our proposed methods and results. We will also give the audience some statistical information proving our case. However, during our one and a half year long research we gathered a lot of testing information which we simply cannot discuss within our presentation without killing any interest in our findings. We will try to balance all what we mentioned here to keep the audience happy and interested in the discussion.