George Ou

George Ou, a former ZDNet blogger, is an IT consultant specializing in Servers, Microsoft, Cisco, Switches, Routers, Firewalls, IDS, VPN, Wireless LAN, Security, and IT infrastructure and architecture.</p>

Latest Posts

Blue Pill: The first effective Hypervisor Rootkit

Blue Pill: The first effective Hypervisor Rootkit

Unlike SubVirt which relied on commercial virtualization technology like VMware or Virtual PC, Blue Pill uses hardware virtualization and allows the OS to continue talking directly to the hardware. Commercial virtualization software has to emulate full I/O functionality from storage to networking to video and it would be exceedingly simple to detect driver changes. Furthermore, it would take a fairly complex physical to virtual migration to get SubVirt installed on the system. Blue Pill on the other hand can do an on-the-fly install and simply shift your Operating System from direct control of the physical computer to a virtualized state living under the control of Blue Pill. Blue Pill then acts as an ultra-thin Hypervisor that lies dormant most of the time using virtually zero overhead and waits for "interesting" events such as keyboard input.

August 15, 2006 by in Virtualization