Scispace (Formerly Typeset)
  1. Home
  2. Topics
  3. Background debug mode interface
  4. 2018
  1. Home
  2. Topics
  3. Background debug mode interface
  4. 2018
Showing papers on "Background debug mode interface published in 2018"
Journal Article•10.1109/TDSC.2016.2545671•
Towards Transparent Debugging

[...]

Fengwei Zhang1, Kevin Leach2, Angelos Stavrou3, Haining Wang4•
Wayne State University1, University of Virginia2, George Mason University3, University of Delaware4
01 Mar 2018-IEEE Transactions on Dependable and Secure Computing
TL;DR: MalT, a debugging framework that employs System Management Mode, a CPU mode in the x86 architecture, to transparently study armored malware, does not depend on virtualization or emulation and thus is immune to threats targeting such environments.
Abstract: Traditional malware analysis relies on virtualization or emulation technology to run samples in a confined environment, and to analyze malicious activities by instrumenting code execution. However, virtual machines and emulators inevitably create artifacts in the execution environment, making these approaches vulnerable to detection or subversion. In this paper, we present MalT , a debugging framework that employs System Management Mode, a CPU mode in the x86 architecture, to transparently study armored malware. MalT does not depend on virtualization or emulation and thus is immune to threats targeting such environments. Our approach reduces the attack surface at the software level, and advances state-of-the-art debugging transparency. MalT embodies various debugging functions, including register/memory accesses, breakpoints, and seven stepping modes. Additionally, MalT restores the system to a clean state after a debugging session. We implemented a prototype of MalT on two physical machines, and we conducted experiments by testing an array of existing anti-virtualization, anti-emulation, and packing techniques against MalT . The experimental results show that our prototype remains transparent and undetected against the samples. Furthermore, debugging and restoration introduce moderate but manageable overheads on both Windows and Linux platforms.

12 citations

Tools

SciSpace AgentBiomedical AgentSciSpace RecruitSciSpace for EnterpriseAgent GalleryChat with PDFLiterature ReviewAI WriterFind TopicsParaphraserCitation GeneratorExtract DataAI DetectorCitation Booster

Learn

ResourcesLive Workshops

SciSpace

CareersSupportBrowse PapersPricingSciSpace Affiliate ProgramCancellation & Refund PolicyTermsPrivacyData Sources

Directories

PapersTopicsJournalsAuthorsConferencesInstitutionsCitation StylesWriting templates

Extension & Apps

SciSpace Chrome ExtensionSciSpace Mobile App

Contact

support@scispace.com
SciSpace

© 2026 | PubGenius Inc. | Suite # 217 691 S Milpitas Blvd Milpitas CA 95035, USA

soc2
Secured by Delve