-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/895/joanna-we-can-detect-bluepill-let-us-prove-it/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
This is interesting indeed!
What I do like is, "you can't peg the CPU for more than a second because it will be a drag for users". Like the performance cost of having SVM/VTX enabled isn't?
If so, there is always Yi Min Wang's Ghostbuster trick from Microsoft Research.
Persistent stealthy rootkits, in the face of a defender who can reboot the system and has a trusted BIOS and trusted media, are always detectible, unless the rootkit author solves the program-intent-detection problem (aka, the AV version of the Halting problem), gives up on stealth (not a rootkit), or gives up on persistent (reboot clears rootkit)