Skip to main content

Malware vs. virtual machines

posted onJanuary 25, 2007
by hitbsecnews

As virtual machines and various emulators have become commonplace in analysis of malicious code, malicious code has started to fight back. This hot topic was recently covered at AVAR 2006 conference by Peter Ferrie, a researcher at Symantec anti-virus research center.

Ferrie has published a paper where he discusses how various virtual machines can be detected and how to defend against them. ?The focus of the paper is the different ways in which various virtual machines can be detected. There are detections for VMware, VirtualPC, Parallels, Bochs, Hydra (though the published methods have since been fixed), QEMU, Atlantis and Sandbox, along with lots of source code,? writes Ferrie in a post on Symantec?s blog.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th