Controlling the speed of virtual time for malware deactivation

  • Authors:
  • Keisuke Okamura;Yoshihiro Oyama

  • Affiliations:
  • The University of Electro-Communications;The University of Electro-Communications

  • Venue:
  • Proceedings of the Asia-Pacific Workshop on Systems
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

We propose a mostly OS-independent, VMM-based method that deactivates malware at the granularity of a process. Specifically, the method slows malware processes extremely by shortening the timer interrupt intervals and modifying the system time value: the amount of time that elapses from the boot. We implemented a VMM based on the method, named HyperSlow, and confirmed that it can slow a particular process considerably.