Microsoft refutes hypervisor attack claim

Senior Microsoft security strategist Steve Riley has used the vendor's Tech.Ed conference in Sydney this week to rebut claims by a Polish researcher that Microsoft's hypervisor software could be maliciously replaced on PCs without administrators knowing.

Microsoft's Steve Riley
(Credit: Microsoft)

The hypervisor is the portion of Microsoft's operating system that controls virtual operating system instances. Researcher, Joanna Rutkowska, has caused a debate over the past several years about developing a hypervisor rootkit that could go undetected on a PC.

"Her insistence is that you can replace the hypervisor without anybody knowing... Our assertion is that this is incorrect," Riley told the audience. "First of all, to do these attacks you need to become administrator at the root. So, that's going to be, on an appropriately configured machine, an exceedingly difficult thing to happen."

Even if an attacker's malware did gain root access, therefore allowing them to replace the hypervisor, the replacement itself would be an imperfect copy, according to Riley.

"Because you (the attacker) didn't subject your own replacement hypervisor through the thorough design review that ours did, I'll bet your hypervisor is probably not going to implement 100 per cent of the functionality as the original one," he said. "There will be a gap or two and we will be able to detect that."

An attacker's malware would also behave differently to the original hypervisor, resulting in changes to network, processing and disk activity, which should cause alarm bells for security professionals.

"I mean, the whole reason for doing this is so you can take over the machine," he explained. "It is entirely possible to detect if the root operating system has been compromised and if the hypervisor has been replaced."

So where does that leave the security professional who manages these systems? According to Riley, exactly where they were before the rise of virtual machines.

"You have to ask: is there malware on my system? You can be 100 per cent certain there is no malware that you can detect, but less than 100 per cent certain that there is no malware at all. Now, ladies and gentlemen, isn't this true of every computer we already have? There is no difference just because it's virtualisation.

"Don't let the hype machines cloud your understanding of what you need to do. Apply your knowledge to the next evolutionary step, but don't expect that everything you have learned is something you have to throw away."

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

I'm a payed up lib member who has voted Labor in the last 2 federal elections. I had the previlege of speaking to Mr Turnball 3 months ag...

0 minute ago by spazmanaught on NBN contracts may be left alone: Turnbull

Good to see Westpac's concentrating on the real IT issues !

4 minutes ago by jeff_syd on Westpac board goes paperless with iPads

Fed Govt steps up on shared cloud plan - ZDNet Australia: The Australian Government Information... http://t.co/lIRepJnI #cloud #news #AU

by http://t.co/vmlLt4bh: Fed Govt steps up on shared cloud plan: The Federal Government has proposed advancing it... http://t.co/YO4h9UI8

Google closes Motorola Mobility deal http://t.co/BkGBmagB

Fed Govt steps up on shared cloud plan: The Federal Government has proposed advancing its shared cloud strategy ... http://t.co/Yc2QBYPx

Fed Govt steps up on shared cloud plan - ZDNet Australia: Fed Govt steps up on shared cloud planZDNet AustraliaT... http://t.co/5bb7Wz1G

BYOD: What the people think | ZDNet http://t.co/0EMHmiCg

Anonymous hacks Bureau of Justice, leaks 1.7GB of data - http://t.co/HFqI12Q9 #InfoSec

Fed Govt steps up on shared cloud plan: The Federal Government has proposed advancing its shared cloud strategy ... http://t.co/dq95elts

Fed Govt steps up on shared cloud plan: The Federal Government has proposed advancing its shared cloud strategy ... http://t.co/ReA93WL9

Consumer Reports recommends Nokia Lumia 900 for dads and grads http://t.co/LsWkcsU0

#Spotify finally goes Live in Australia http://t.co/VFP8Xq8U

"@ZDNet: SAP gets huge cloud and extended business process boost with Ariba acquisition http://t.co/Ro04GlP4" ->#SAP strengthening its cloud

RT @zdnetaustralia: The Westpac board have gone paperless using iPads and a secure, home-grown app environment: http://t.co/F1d17bvF ^LH

BYOD: What the people think http://t.co/5Mh2x0u9 via @zite #byotchat #edtech

Interesting..Who uses Twitter for job search? http://t.co/KuWVItXK @zdnetcharlie

SAP gets huge cloud and extended business process boost with Ariba acquisition: SAP is focused on global cloud g... http://t.co/75ps1wG3

Microsoft exec: Dynamics CRM, AX aims to feast Oracle, SAP switchers http://t.co/XiC912eT

#SAP wants to be the biggest cloud player by 2015... http://t.co/fLwejro7

RT @playbiggeradv: #SAP wants to be the biggest cloud player by 2015... http://t.co/fLwejro7

Handy overview of #Android 's major #security flaws: http://t.co/oiVrKSHb #mobile #infosec

The implications of NZ school Principals demanding access to student mobile devices | ZDNet http://t.co/jMSJXzpT

Google closes Motorola buy: http://t.co/9ezoLnSg

War talk dominates #AusCERT 2012 - http://t.co/WbuTt174 - #security #cyber

Nuance launches in car voice activated platform (Zack Whittaker ZDNet) http://t.co/9mFEA93c

Sage simplifies SMB payment management http://t.co/gbAKq1ku

A farewell to democracy: Kaspersky http://t.co/zE2SAGol via @zdnetaustralia

Private Cloud: 'Everyone’s got one. Where's yours?': Promising the business a cloud delivered within your own ... http://t.co/jCsDqPlj

BYOD: What the people think http://t.co/hR1pokPG

@ZDNet
R they joking? iPhone only way 2 go!
New 5 out in October (we think) & will kill all copycat phones, AGAIN!!

Android's biggest security flaws - Security - News - ZDNet Australia http://t.co/6nYZRvhh
@sjshock

Google: We now own Motorola Mobility http://t.co/oeFgovzl

@dougsteelman RT @dellsecureworks : Security researcher Tim Vidas of Dell SecureWorks outlines problems with the Androi…http://t.co/BE4LmItr

EMC hones focus on hybrid cloud, big data http://t.co/To6Qpsz4 #bigdata #XBRL #GRC $$

#Security researcher Tim Vidas of @DellSecureworks outlines some concerns with the #Android operating system: http://t.co/gV8MgCiN

Article and Infographic: Retailers attracting the next-gen customer http://t.co/UL3E2Fct #socialmedianews

I am not sure how this issue becomes an attack on Mr Turnbull. But I guess he is fair game. In any event I would have thought a Ddos woul...

10 hours ago by Doubt on National Botnet Network coming: Earthwave

I still use 98SE. Windows ME was an abortion in a bucket and Vista was ME without the bucket. My screen may look boring, but I jumped str...

10 hours ago by Treknology on Microsoft admits Vista was 'cheesy'

This story has been voted 10 times in the last 24 hours!

11 hours ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

11 hours ago, Lenovo ThinkPad 3G tablet (32GB)

Well I don't know what they have done with their EFTPOS machines, local one in WA Coles Express I used this morning and I normally do "ch...

11 hours ago by harryinthesoup on Coles ditches PINs in payment pilot

6.7 M last ditch attempt - interesting - The Auckland region (population 1.4 mil) has estimated to have spent less than this in total ...

14 hours ago by debsteele on Vic scraps HealthSMART system

Interesting - no mention of Win 98/ME/2000 ... which heralded Internet access for millions of users ? I thought Win 98/ME would be the mo...

16 hours ago by gouranga on Microsoft admits Vista was 'cheesy'

An Application like Good from Good Technologies does the same thing, working with the enterprise email server and is off the shelf.

16 hours ago by Helpdesk123 on Westpac board goes paperless with iPads

Never mind a "B+" version, go for "C" and put in a few extras. I'd like a high speed ADC (100Msps) but that's just me... Final size? Equ...

17 hours ago by sa_penguin on Raspberry Pi architect mulls design change

what a non-story. these thing happen all the time. is zdnet short on material?

17 hours ago by paulwrussell on Spotify launch suffers redirect bungle

4 months old phone died. Took 6 weeks, three visits to the authorised repairer (Fonebiz) to "fix it". 2nd hand untested parts used, I say...

17 hours ago by paracin on Sony Ericsson Xperia Arc S

It's easy to rubbish an old operating system long after the rest of the world has already passed judgement upon it. I would be far more i...

18 hours ago by ramnet on Microsoft admits Vista was 'cheesy'

If Vista is cheesy, Metro is an over-ripe Stilton.

19 hours ago by meski on Microsoft admits Vista was 'cheesy'

you are kidding right - what qualification do you have to make such wildy stupid statements - do you really have customers who pay you fo...

19 hours ago by rant rant rant on National Botnet Network coming: Earthwave

Exactly. There are two topics of discussion, that are co-mingled; 1) Unauthorized software was put on the company device, by an IT person...

22 hours ago by lamont on ABC's Bitcoin miner tackled in minutes

First off, Bitcoin is not a virus. Second off, the only way to generate Bitcoins, is by using a Bitcoin miner. More information on this h...

1 day ago by rizowski on ABC's Bitcoin miner tackled in minutes

When an operating system is sold it should not launch until an approved security service is purchased online with a list of approved supp...

1 day ago by Kevin Cobley on National Botnet Network coming: Earthwave

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

1 day ago by anonymuos on Microsoft admits Vista was 'cheesy'

Gotta agree. For our Burnie, Tas. internet, we have a 1.5MB download speed adls connection through exetel using testra copper line. ADS...

1 day ago by brozza on Broadband Speedtest

Well the message certainly is clear. Never do anything because something might happen. Seriously it seems to me "Earthwave" just want to...

1 day ago by Hubert Cumberdale on National Botnet Network coming: Earthwave

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar