articleACM SIGOPS Operating Systems ReviewDec 31, 2002Closed access

ReVirt

University of Michigan

Indexed incrossref

Abstract

Current system loggers have two problems: they depend on the integrity of the operating system being logged, and they do not save sufficient information to replay and analyze attacks that include any non-deterministic events. ReVirt removes the dependency on the target operating system by moving it into a virtual machine and logging below the virtual machine. This allows ReVirt to replay the system's execution before, during, and after an intruder compromises the system, even if the intruder replaces the target operating system. ReVirt logs enough information to replay a long-term execution of the virtual machine instruction-by-instruction. This enables it to provide arbitrarily detailed observations about…

Citation impact

805
total citations
FWCI
15.48
Percentile
100%
References
24
Citations per year

Authors

5

Topics & keywords

Keywords
  • Computer science
  • Operating system
  • Overhead (engineering)
  • Virtual machine
  • Virtualization
  • User space
  • Logging
  • Kernel (algebra)
No related works found for this paper.