<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/oai-pmh.xsl"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-09-19T16:31:45Z</responseDate>
  <request identifier="oai:www.ideals.illinois.edu:2142/78671" metadataPrefix="etdms" verb="GetRecord">https://www.ideals.illinois.edu/oai-pmh</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:www.ideals.illinois.edu:2142/78671</identifier>
        <datestamp>2023-07-11</datestamp>
        <setSpec>col_2142_5131</setSpec>
        <setSpec>col_2142_10761</setSpec>
        <setSpec>com_2142_5130</setSpec>
        <setSpec>com_2142_10755</setSpec>
        <setSpec>com_2142_234</setSpec>
      </header>
      <metadata>
        <thesis xmlns="http://www.ndltd.org/standards/metadata/etdms/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xsi:schemaLocation="http://www.ndltd.org/standards/metadata/etdms/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdms11.xsd http://purl.org/dc/elements/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdmsdc.xsd">
          <dc:date>2015-04-27</dc:date>
          <dc:date>2015-5</dc:date>
          <dc:creator>Wang, Gary L</dc:creator>
          <dc:date>2015-07-22T22:33:55Z</dc:date>
          <dc:date>2015-07-22T22:33:55Z</dc:date>
          <dc:date>2017-07-23T09:15:19Z</dc:date>
          <dc:date>2015-05</dc:date>
          <dc:description>Virtualization technology has enabled powerful security monitoring techniques, such as virtual machine introspection (VMI). These monitoring techniques, however, rely on the assumed isolation of virtualized environments from the hypervisor. We show that there are still some events that can be observed that break this isolation. External observers can discern when virtual machines are suspended due to hypervisor activity, and can use this information to mount advanced attacks that go undetected by VMI monitoring systems. We demonstrate some example attacks against realistic monitors using our technique, and discuss existing and potential defenses against these kinds of attacks.</dc:description>
          <dc:description>Submission published under a 24 month embargo labeled 'U of I only', the embargo will last until 2017-05-01</dc:description>
          <dc:description>The student, Gary Wang, accepted the attached license on 2015-04-24 at 14:37.</dc:description>
          <dc:description>The student, Gary Wang, submitted this Thesis for approval on 2015-04-24 at 14:48.</dc:description>
          <dc:description>This Thesis was approved for publication on 2015-04-27 at 17:02.</dc:description>
          <dc:description>DSpace SAF Submission Ingestion Package generated from Vireo submission #8096 on 2015-07-22 at 14:18:52</dc:description>
          <dc:description>Made available in DSpace on 2015-07-22T22:33:55Z (GMT). No. of bitstreams: 2
WANG-THESIS-2015.pdf: 1084800 bytes, checksum: ef73b7149b1241268e3eca20b5ea70b1 (MD5)
LICENSE.txt: 4206 bytes, checksum: aa16f144037dc9dafdda360d1f08fa11 (MD5)
  Previous issue date: 2015-04-27</dc:description>
          <dc:description>Embargo set by: Seth Robbins for item 79912
Lift date: 2017-07-22T22:34:16Z
Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system</dc:description>
          <dc:description>U of I Only Restriction Lifted for Item 79912 on 2017-07-23T09:15:19Z.</dc:description>
          <dc:format>application/pdf</dc:format>
          <dc:identifier>http://hdl.handle.net/2142/78671</dc:identifier>
          <dc:language>en</dc:language>
          <dc:rights>Copyright 2015 Gary Wang</dc:rights>
          <dc:subject>security</dc:subject>
          <dc:subject>virtual machine introspection (VMI)</dc:subject>
          <dc:subject>side-channel</dc:subject>
          <dc:subject>cloud</dc:subject>
          <dc:title>Hypervisor introspection: a technique for evading passive virtual machine monitoring</dc:title>
          <dc:type>text</dc:type>
          <dc:type>text</dc:type>
          <degree>
            <department>Computer Science</department>
            <discipline>Computer Science</discipline>
            <grantor>University of Illinois at Urbana-Champaign</grantor>
            <level>Thesis</level>
            <name>M.S.</name>
          </degree>
        </thesis>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
