Virtual machine introspection explained

In computing, virtual machine introspection (VMI) is a technique "for monitoring the runtime state of a system-level virtual machine (VM)", which is helpful for debugging or forensic analysis.

The term introspection in application to the virtual machines was introduced by Garfinkel and Rosenblum.[1] They invented an approach for "protecting a security application from attack by malicious software" and called it VMI. Now VMI is a common term for different virtual machine forensics and analysis methods. VMI-based approaches are widely used for security applications, software debugging, and systems management.

VMI tools may be located inside or outside the virtual machine and act by tracking the events (interrupts, memory writes, and so on) or sending the requests to the virtual machine. Virtual machine monitor usually provides low-level information like raw bytes of the memory. Converting this low-level view into something meaningful for the user is known as the semantic gap problem. Solving this problem requires analysis and understanding of the systems being monitored.

VMI within the virtual machine

Programs running inside VM may provide information about other processes. This information may be sent through network interface or some virtual devices like serial port. The examples of in vivo introspection programs are WinDbg[2] or GDB[3] servers that interact with the remote debugger.

The drawback of this approach is that it requires functioning OS within the VM. If OS hangs or isn't loaded yet, the introspection agent couldn't work.

VMI outside the virtual machine

VMI tools may be implemented within the virtual machine monitor[4] [5] or as a separate programs that capture information (e.g., contents of the memory) from the virtual machine monitor.Then this data has to be interpreted to understand the processes in the system. One of the popular tools for such interpretation is Volatility framework.[6] This framework contains profiles for many popular operating systems and may extract different information like process tree or list of the kernel objects.

Notes and References

  1. https://suif.stanford.edu/papers/vmi-ndss03.pdf A Virtual Machine Introspection Based Architecture for Intrusion Detection
  2. Web site: 2021-12-15 . Remote Debugging Using WinDbg - Windows drivers . 2023-10-13 . learn.microsoft.com . en-us.
  3. https://sourceware.org/gdb/onlinedocs/gdb/Server.html Using the gdbserver Program
  4. Web site: Virtual Machine Introspection - Xen . 2023-10-13 . wiki.xenproject.org.
  5. Book: Dovgalyuk . Pavel . Fursova . Natalia . Vasiliev . Ivan . Makarov . Vladimir . Proceedings of the 2017 11th Joint Meeting on Foundations of Software Engineering . QEMU-based framework for non-intrusive virtual machine instrumentation and introspection . 2017-08-21 . https://doi.org/10.1145/3106237.3122817 . ESEC/FSE 2017 . New York, NY, USA . Association for Computing Machinery . 944–948 . 10.1145/3106237.3122817 . 978-1-4503-5105-8. 43470460 .
  6. https://github.com/volatilityfoundation/volatility Volatile memory extraction utility framework