Introduction to Virtual Machine Introspection for System Monitoring of Legacy Windows Environments
Ngamia Djabiri, Julie
Promotor(s) :
Donnet, Benoît
Date of defense : 8-Sep-2025/9-Sep-2025 • Permalink : http://hdl.handle.net/2268.2/24935
Details
| Title : | Introduction to Virtual Machine Introspection for System Monitoring of Legacy Windows Environments |
| Author : | Ngamia Djabiri, Julie
|
| Date of defense : | 8-Sep-2025/9-Sep-2025 |
| Advisor(s) : | Donnet, Benoît
|
| Committee's member(s) : | Hault, Olivier
Mathy, Laurent
Boigelot, Bernard
|
| Language : | English |
| Keywords : | [en] Virtual Machine Introspection [en] Legacy Systems [en] Windows OS |
| Discipline(s) : | Engineering, computing & technology > Computer science |
| Funders : | Level IT |
| Institution(s) : | Université de Liège, Liège, Belgique |
| Degree: | Master : ingénieur civil en informatique, à finalité spécialisée en "computer systems security" |
| Faculty: | Master thesis of the Faculté des Sciences appliquées |
Abstract
[en] This master's thesis explores the field of Virtual Machine Introspection (VMI) with two focuses: firstly, to establish a solid understanding of VMI, its principles, and its implementation in existing frameworks. Secondly, to apply this knowledge to extend an existing VMI framework, DRAKVUF, to support legacy Windows systems. The work demonstrates the feasibility and value of extending VMI capabilities to legacy systems.
This master's thesis is organized in the following way: Chapter 1 is the introduction, Chapter 2 the objectives and structure of the thesis, Chapter 3 review the technical background needed to understand this work, Chapter 4 presents the virtualized setups used to test the frameworks explored, Chapter 5 introduces VMI for system monitoring, exploring both the broad VMI concept and the technical implementations of VMI by VMI frameworks, Chapter 6 performs an exploratory study of API monitoring with and without VMI, reviewing both traditional API monitoring techniques and frameworks, and a concrete VMI API monitoring, Chapter 7 presents the implementation, testing, and evaluation work made in this thesis (although other chapters also contain practical parts), and finally, Chapter 8 presents the conclusions.
File(s)
Document(s)
Master_Thesis.pdf
Description:
Size: 6.57 MB
Format: Adobe PDF
Annexe(s)
Summary.pdf
Description:
Size: 33.14 kB
Format: Adobe PDF
Cite this master thesis
The University of Liège does not guarantee the scientific quality of these students' works or the accuracy of all the information they contain.

Master Thesis Online

