[cap-talk] Virtual Machine Based Rootkits

Karp, Alan H alan.karp at hp.com
Thu Aug 3 18:13:16 EDT 2006


David Hopwood wrote:
> 
> That's not quite accurate; most VMMs are detectable, and 
> AFAIK all VMMs
> that run on x86 hardware (VT, Pacifica or otherwise) are detectable.
> 
That's because x86 is not fully virtualizable.  Rutkowska is working on
architectures that are.

_________________________
Alan Karp
Principal Scientist
Virus Safe Computing Initiative
Hewlett-Packard Laboratories 
1501 Page Mill Road
Palo Alto, CA 94304
(650) 857-3967, fax (650) 857-7029
https://ecardfile.com/id/Alan_Karp
http://www.hpl.hp.com/personal/Alan_Karp/
  
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Karp, Alan H.vcf
Type: text/x-vcard
Size: 423 bytes
Desc: Karp, Alan H.vcf
Url : http://www.eros-os.org/pipermail/cap-talk/attachments/20060803/4d73b10c/attachment.vcf 


More information about the cap-talk mailing list