Introduction to Virtual Machine Introspection for System Monitoring of Legacy Windows Environments
Ngamia Djabiri, Julie
Promoteur(s) :
Donnet, Benoît
Date de soutenance : 8-sep-2025/9-sep-2025 • URL permanente : http://hdl.handle.net/2268.2/24935
Détails
| Titre : | Introduction to Virtual Machine Introspection for System Monitoring of Legacy Windows Environments |
| Auteur : | Ngamia Djabiri, Julie
|
| Date de soutenance : | 8-sep-2025/9-sep-2025 |
| Promoteur(s) : | Donnet, Benoît
|
| Membre(s) du jury : | Hault, Olivier
Mathy, Laurent
Boigelot, Bernard
|
| Langue : | Anglais |
| Mots-clés : | [en] Virtual Machine Introspection [en] Legacy Systems [en] Windows OS |
| Discipline(s) : | Ingénierie, informatique & technologie > Sciences informatiques |
| Organisme(s) subsidiant(s) : | Level IT |
| Institution(s) : | Université de Liège, Liège, Belgique |
| Diplôme : | Master : ingénieur civil en informatique, à finalité spécialisée en "computer systems security" |
| Faculté : | Mémoires de la Faculté des Sciences appliquées |
Résumé
[en] This master's thesis explores the field of Virtual Machine Introspection (VMI) with two focuses: firstly, to establish a solid understanding of VMI, its principles, and its implementation in existing frameworks. Secondly, to apply this knowledge to extend an existing VMI framework, DRAKVUF, to support legacy Windows systems. The work demonstrates the feasibility and value of extending VMI capabilities to legacy systems.
This master's thesis is organized in the following way: Chapter 1 is the introduction, Chapter 2 the objectives and structure of the thesis, Chapter 3 review the technical background needed to understand this work, Chapter 4 presents the virtualized setups used to test the frameworks explored, Chapter 5 introduces VMI for system monitoring, exploring both the broad VMI concept and the technical implementations of VMI by VMI frameworks, Chapter 6 performs an exploratory study of API monitoring with and without VMI, reviewing both traditional API monitoring techniques and frameworks, and a concrete VMI API monitoring, Chapter 7 presents the implementation, testing, and evaluation work made in this thesis (although other chapters also contain practical parts), and finally, Chapter 8 presents the conclusions.
Fichier(s)
Document(s)
Master_Thesis.pdf
Description:
Taille: 6.57 MB
Format: Adobe PDF
Annexe(s)
Summary.pdf
Description:
Taille: 33.14 kB
Format: Adobe PDF
Citer ce mémoire
L'Université de Liège ne garantit pas la qualité scientifique de ces travaux d'étudiants ni l'exactitude de l'ensemble des informations qu'ils contiennent.

Master Thesis Online

