HInjector: Injecting Hypercall Attacks for Evaluating VMI-based Intrusion Detection Systems (Poster Paper)

Aleksandar Milenkoski, Bryan D. Payne, Nuno Antunes, Marco Vieira, and Samuel Kounev
Germany, USA, Portugal
In this paper, we present HInjector, a customizable framework for injecting hypercall attacks during regular operation of a paravirtualized guest VM (virtual machine) in a Xen-based environment. The goal of HInjector is to exercise the sensors of a typical VMI(virtual machine introspection)-based intrusion detection system.
