Submitted:
11 September 2025
Posted:
15 September 2025
You are already at the latest version
Abstract
Keywords:
1. Introduction
- We prepared a portable disk image containing recent releases of Ubuntu, XEN with QEMU, DRAKVUF, SmartVMI, our benchmark tool bpbench, and tools for VM snapshot management. We make the image available to reproduce our measurements on matching hardware or repeat the measurements on other systems.
- We provide breakpoint-benchmark results measured with the previously mentioned disk image on 20 devices with Intel Core processors ranging from the 4th to the 13th generation.
2. Background
2.1. VMI Software Architecture
2.2. Hyper-Breakpoint Handling
2.2.1. Instruction Repair (1)
2.2.2. Instruction Emulation (2)
2.2.3. SLAT View Switch (altp2m) (3)
2.3. Acceleration: Breakpoint Handling by the Hypervisor
2.4. Hiding Breakpoints for Stealth
| Name | VMI Software | MP-safe | Single-step | Trap | Sequence |
|---|---|---|---|---|---|
| Repair Instruction | (not implemented) | no | yes | EPT read trap | repair instruction, single step read, patch instriction (INT3) |
| Read Emulation | SmartVMI | yes | no | EPT read trap | emulate read |
| SLAT View Switch | DRAKVUF | yes | yes | EPT read trap | SlatSwitch(origin), single step read, SlatSwitch(patched) |
3. Approach
3.1. A Metric for Breakpoint Performance
3.2. Choosing the Hypervisor
3.3. Hardware Platform Evaluation Set
3.4. Software Setup

3.5. The bpbench Benchmark Tool
3.6. Configurations to Improve Measurement Accuracy
3.6.1. Focus on Process Priority
3.6.2. CPU Pinning
3.6.3. Disabling SMT
3.6.4. Fix CPU Clock Speed
3.7. Workloads
- WL1: Execute the breakpoint. This workload is supposed to measure how long it takes the whole VMI stack to handle a breakpoint. There are a multitude of factors that comprise this latency: VM transitions (exits and entries), processing in the hypervisor, communication between the hypervisor and the VMI application, processing in the VMI application.
- WL2: Execute the page with the breakpoint. Techniques such as altp2m make changes to the EPT configuration of individual vCPUs, which could also impact caching and TLB performance. If it has an impact on performance, this may be noticeable when other instructions are executed on the same page where the breakpoint is located. The previous workload does not reflect that, so this one is supposed to measure the latency of executing the breakpoint as well as additional instructions (NOP) that are located on the same page.
| Breakpoint handling method | VMI software | WL1: execute breakpoint | WL2: execute page with breakpoint |
|---|---|---|---|
| Instr_Repair | SmartVMI | exec_bp_rep | exec_page_rep |
| Instr_Emulation | SmartVMI | exec_bp_emul | exec_page_emul |
| Altp2m | DRAKVUF | exec_bp_altp2m | exec_page_altp2m |
| Altp2m_FSS | DRAKVUF | exec_bp_altp2m_fss | exec_page_altp2m_fss |
- WL3: Reading the breakpoint. The stealth-related breakpoint hiding methods using EPT permissions to realize the read trap on the page where the breakpoint is located cause overhead for the same reasons as mentioned in WL1. This workload is designed to quantify this latency by reading from the exact same memory location where the breakpoint is placed.
- WL4: Reading the page with the breakpoint. The used read trap based on EPT permissions has page-granularity. This trap not only intercepts and handles the read operation at the address where the breakpoint is located, but it also triggers for every other read operation on the page. This workload reflect this fact and perform multiple read operation on all bytes of the whole page where the breakpoint is located. The statement that code pages are practically hardly ever read is not true in every case. There is a real use case for this workload, because code integrity checks, such as those performed by KPP / PathGuard, involve reading entire code pages.
| Breakpoint hiding method | VMI software | WL3: read breakpoint | WL4: read page with breakpoint |
|---|---|---|---|
| Read_Emulation | SmartVMI | read_bp_emul | read_page_emul |
| Altp2m | DRAKVUF | read_bp_altp2m | read_page_altp2m |
4. Hardware Platforms
- all Efficient-cores (on processors with performance and efficient cores)
- Simultaneous Multithreading (SMT) aka Intel Hyperthreading (Intel HT)
- Intel SpeedStep
- Intel SpeedShift
- Intel Turbo Boost Mode
- CPU Power Management
- CPU Power Saving Mode (C-states)
4.1. Special Cases
-
Intel NUC7i5DNHE (7th gen i5 7300U)
- -
- Processor model has only two cores (0,1)
- -
- We chose to run system threads on core 0 and the VM, VMM process and VMI software on core 1.
- -
- The system has only 8GB main memory. We had to configure both VMs down to give 4GB to the control VM (Dom0) and 3.6GB to the Windows VM (Domu).
-
Fujitsu ESPRIMO D757 (6th gen i3 6100)
- -
- Processor model has only two cores (0,1)
- -
- Similar pinning/memory management as the previous device
-
Lenovo ThinkPad L14 Gen3 (12th gen i7 1265U)
- -
- Processor model has only two performance cores (0,1) and 8 efficient cores (2,3,4,5,6,7,8,9).
- -
- Control VM (dom0) was running on CPU 0,1,2,3 (two performance cores, two efficient cores).
- -
- SmartVMI and DRAKVUF were running on CPU 1 (performance core).
- -
- Windows VM with bpbech and VMM were running on CPU 2 (efficiency core).
- -
- All other system processes were pinned to CPU 0,1,3.
-
InfinityBook Pro Gen8 (13th gen i7 13700H)
- -
- Hyperthreading (SMT) could not be disabled via firmware setup.
- -
- We enforced that only one logical CPU of each HT core was used by assigning only the first logical CPU of each core to the VMs via XEN config, with the effect that Hyperthreading was not used.
4.2. XEN Performance Adjustments
5. Measurements
5.1. Initial Analysis and Filtering

5.2. Comparison of the Breakpoint Methods

- Breakpoint handling mechanism using SLAT view switching (exec_bp_altp2m, exec_page_altp2m) incurs the same tempral costs than the SLAT view switching based breakpoint hiding method (read_bp_altp2m, read_page_altp2m). This makes sense because both based on the same approach and operations (EPT switch, single-step execution, EPT switch back).
- The fast single-step extension (FSS) XEN provides makes the breakpoint handling quite a bit faster. We may be able to estimate the costs of switching from XEN to DRAKVUF and back again by comparing the measurement results from exec_bp_altp2m and exec_bp_altp2m_fss, because it is precisely this switch that is made unnecessary by the FSS optimization. The FSS option in DRAKVUF only optimizes the breakpoint handling, for the stealth-related mechanism of read operation trapping FSS will not be used. So the measurements of read_bp_altp2m show the same results regardless of whether FSS is enabled.
- The instruction repair method (exec_bp_rep) is quite a bit slower than the SLAT view switching variant (exec_bp_altp2m). This is in line with our expectations, because the repair mechanism has the same number of transitions as the SLAT view switching approach, but instead of the VMCS manipulation, a writing to guest memory will be performed, which apparently is a more expensive operation.
- The emulation of the origin instruction as a breakpoint handling method (exec_bp_emul) has roughly the same speed as the stealth-related read emulation (read_bp_emul) in all measurements on all machines, which seems reasonable.
5.3. SmartVMI Anomalies

5.4. Measurements on All Hardware Platforms


5.5. Does Hardware Advancement Have an Effect?
6. Related Work
7. Conclusion
7.1. Summary and Discussion
7.2. Future Work
Author Contributions
Funding
Data Availability Statement
Acknowledgments
Use of Artificial Intelligence
Conflicts of Interest
References
- Garfinkel, T.; Rosenblum, M.; et al. A virtual machine introspection based architecture for intrusion detection. In Proceedings of the Ndss. San Diega, CA, 2003, Vol. 3, pp. 191–206.
- wook Baek, H.; Srivastava, A.; Van der Merwe, J. CloudVMI: Virtual Machine Introspection as a Cloud Service. In Proceedings of the 2014 IEEE International Conference on Cloud Engineering. IEEE, IEEE, 3 2014, pp. 153–158. [CrossRef]
- Jiang, X.; Wang, X.; Xu, D. Stealthy malware detection through VMM-based ‘out-of-the-box’semantic view. In Proceedings of the Proceedings of the 14th ACM conference on Computer and communications security. ACM, 10 2007, Vol. 10, CCS07, pp. 128–138. [CrossRef]
- Dinaburg, A.; Royal, P.; Sharif, M.; Lee, W. Ether: malware analysis via hardware virtualization extensions. In Proceedings of the Proceedings of the 15th ACM conference on Computer and communications security. ACM, 10 2008, CCS08, pp. 51–62. [CrossRef]
- Willems, C.; Hund, R.; Holz, T. Cxpinspector: Hypervisor-based, hardware-assisted system monitoring. Technical report, Ruhr-Universitat Bochum, 2013.
- Dolan-Gavitt, B.; Leek, T.; Zhivich, M.; Giffin, J.; Lee, W. Virtuoso: Narrowing the Semantic Gap in Virtual Machine Introspection. In Proceedings of the 2011 IEEE Symposium on Security and Privacy. IEEE, IEEE, 5 2011, pp. 297–312. [CrossRef]
- Jain, B.; Baig, M.B.; Zhang, D.; Porter, D.E.; Sion, R. SoK: Introspections on Trust and the Semantic Gap. In Proceedings of the 2014 IEEE Symposium on Security and Privacy, 5 2014, pp. 605–620. ISSN: 2375-1207, . [CrossRef]
- Dangl, T.; Taubmann, B.; Reiser, H.P. RapidVMI: Fast and multi-core aware active virtual machine introspection. In Proceedings of the Proceedings of the 16th International Conference on Availability, Reliability and Security, New York, NY, USA, 8 2021; ARES ’21, pp. 1–10. [CrossRef]
- Lengyel, T.K.; 3esca, S.; Payne, B.D.; Webster, G.D.; Vogl, S.; Kiayias, A. Scalability, fidelity and stealth in the DRAKVUF dynamic malware analysis system. In Proceedings of the Proceedings of the 30th Annual Computer Security Applications Conference. ACM, 12 2014, ACSAC ’14, pp. 386–395. [CrossRef]
- Tarral, M. LibVMI: Simplified Virtual Machine Introspection. https://github.com/libvmi/libvmi, 2007. Accessed: 2025-15-01.
- Eikenberg, D. SmartVMI. https://github.com/GDATASoftwareAG/smartvmi, 2021. Accessed: 2025-15-01.
- Reiser, H.P.; Eikenberg, D. SmartVMI - Virtual Machine Introspection (VMI) for memory forensics and machine-learning. http://www.smartvmi.org/, 2021. Accessed: 2025-15-01.
- Lengyel, T. DRAKVUF Black-box Binary Analysis. https://github.com/tklengyel/drakvuf, 2014. Accessed: 2024-12-19.
- Lengyel, T.K. Stealthy monitoring With xen altp2m. https://xenproject.org/blog/stealthy-monitoring-with-xen-altp2m/, 2016. Accessed: 2024-12-17.
- Roccia, T. Evolution of Malware Sandbox Evasion Tactics – A Retrospective Study, 2019.
- Beierlieb, L.; Schmitz, A.; Springer, R.; Dietrich, C.; Iffländer, L. Benchmarking Hyper-Breakpoints for Efficient Virtual Machine Introspection. Electronics 2025, 14. [CrossRef]
- Beierlieb, L. vmi-nix: Nix Packaging and NixOS Modules for VMI. https://github.com/lbeierlieb/vmi-nix/tree/e2f26e840bcb69e85cf790a3a40c790492cd6662, 2025.
- Beierlieb, L. REPAIR: vmi-nix: Nix Packaging and NixOS Modules for VMI. https://github.com/lbeierlieb/smartvmi/tree/c848275674ad19ad7df6fe972852ce2af5db4746, 2025.
- Beierlieb, L. EMULATION vmi-nix: Nix Packaging and NixOS Modules for VMI. https://github.com/lbeierlieb/smartvmi/tree/f0959d7776686a78b0fc7379aeb182a6bb3518a1, 2025.
- Wahbe, R. Efficient data breakpoints. ACM SIGPLAN Notices 1992, 27, 200–212. [CrossRef]
- Wahbe, R.; Lucco, S.; Graham, S.L. Practical data breakpoints: Design and implementation. In Proceedings of the Proceedings of the ACM SIGPLAN 1993 conference on Programming language design and implementation. ACM, 6 1993, Vol. 28, PLDI93, pp. 1–12. [CrossRef]
- Deng, Z.; Zhang, X.; Xu, D. SPIDER: stealthy binary program instrumentation and debugging via hardware virtualization. In Proceedings of the Proceedings of the 29th Annual Computer Security Applications Conference, New York, NY, USA, 2013; ACSAC ’13, p. 289–298. [CrossRef]
- Karvandi, M.S.; Gholamrezaei, M.; Khalaj Monfared, S.; Meghdadizanjani, S.; Abbassi, B.; Amini, A.; Mortazavi, R.; Gorgin, S.; Rahmati, D.; Schwarz, M. HyperDbg: Reinventing Hardware-Assisted Debugging. In Proceedings of the Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, New York, NY, USA, 2022; CCS ’22, p. 1709–1723. [CrossRef]
- Price, G.M. Virtual Breakpoints for x86/64, 2019, [arXiv:cs.OS/1801.09250].

| Name | Implementation | MP-safe | Single-step | Trap | Sequence |
|---|---|---|---|---|---|
| Instruction Repair (1) | SmartVMI Rep | no | yes | INT3 | repair instruction, single step execution, patch instruction (INT3) |
| Instruction Emulation (2) | SmartVMI Emul | yes | no | INT3 | emulate instruction |
| SLAT View Switch (3) | DRAKVUF altp2m (FSS) | yes | yes | INT3 | SlatSwitch(origin), single step execution, SlatSwitch(patched) |
| Component | Version / Configuration |
|---|---|
| Host OS (Dom0) | Ubuntu 24.04.3 LTS, Linux kernel 6.14.0-28-generic |
| Hypervisor | XEN 4.20 |
| VMM | QEMU 9.1.0 |
| Guest OS (DomU) | Windows 10 Education 22H2 (Build 19045.2006) |
| Packet Manager | NIX 2.31.0 |
| BP: altp2m, altp2m_fss | DRAKVUF with LibVMI (internal version) |
| BP: instr_repair, instr_emulation | SmartVMI with LibVMI (NIX build) |
| Benchmark workload | bpbench.exe (Windows VM, Desktop) |
| Year | CPU Gen | CPU Model | Base Clock | System Vendor, Model | Sysbench score |
|---|---|---|---|---|---|
| 2014 | 4th | i7 4790K | 4000 MHz | (custom build desktop PC) | 1292.46 |
| 2015 | 6th | i3 6100 | 3700 MHz | Fujitsu ESPRIMO D757 | 1294.50 |
| 2016 | 7th | i5 7300U | 2600 MHz | Intel NUC7i5DNHE | 908.56 |
| 2017 | 8th | i5 8350U | 1700 MHz | Lenovo ThinkPad T480s | 1231.27 |
| 2018 | 8th | i7 8565U | 1800 MHz | Lenovo Yoga 730 15IWL | 1554.17 |
| 2019 | 8th | i7 8665U | 1900 MHz | Lenovo ThinkPad X390 Yoga | 1644.53 |
| 2019 | 9th | i7 9750H | 2600 MHz | HP OMEN 17 CB0XXX | 1356.64 |
| 2019 | 9th | i7 9850H | 2600 MHz | Lenovo ThinkPad P1 Gen2 | 1529.44 |
| 2018 | 9th | i9 9900K | 3600 MHz | custom build desktop PC | 1270.40 |
| 2020 | 10th | i5 10310U | 1700 MHz | Lenovo ThinkPad T14 Gen1 | 1467.40 |
| 2020 | 11th | i7 1165G7 | 2800 MHz | TUXEDO Book XP14 Gen12 | 2389.13 |
| 2021 | 11th | i7 11800H | 1900 MHz | MSI Katana GF76 11UE | 1961.76 |
| 2022 | 12th | i7 1260P | 2100 MHz | Lenovo ThinkPad T14 Gen3 | 3941.16 |
| 2022 | 12th | i7 1265U | 1800 MHz | Lenovo ThinkPad L14 Gen3 | 1265.30 |
| 2022 | 12th | i7 12700H | 2300 MHz | Lenovo IdeaPad 5 Pro 16IAH7 | 3877.77 |
| 2022 | 12th | i7 12700T | 1400 MHz | Lenovo ThinkStation P360 Tiny | 3867.40 |
| 2023 | 13th | i7 13620H | 2400 MHz | TUXEDO InfinityBook Pro Gen8 | 3602.98 |
| 2023 | 13th | i7 13700H | 2400 MHz | TUXEDO InfinityBook Pro Gen8 | 3453.76 |
| 2022 | 13th | i7 13700K | 3400 MHz | (custom built desktop PC) | 2921.45 |
| 2023 | 13th | i9 13900HX | 2200 MHz | TUXEDO Gemini Gen2 | 4352.94 |
| System | SMT (HT) | SpeedStep / SpeedShift | Turbo Boost | Power Mgmt |
|---|---|---|---|---|
| custom PC (i7 4790K) | disabled | disabled | disabled | not adjustable |
| ESPRIMO D757 (i3 6100) | disabled | disabled | not adjustable | not adjustable |
| NUC (i5 7300U) | disabled | max perf. | disabled | not adjustable |
| ThinkPad T480s (i5 8350U) | disabled | disabled | not adjustable | disabled |
| Yoga 730 15IWL (i7 8565U) | disabled | not adjustable | not adjustable | not adjustable |
| ThinkPad X390 Yoga (i7 8665U) | disabled | disabled | not adjustable | disabled |
| OMEN 17 CB0XXX(i7 9750H) | disabled | not adjustable | not adjustable | not adjustable |
| ThinkPad P1 Gen2 (i7 9850H) | disabled | disabled | not adjustable | disabled |
| custom PC (i9 9900K) | disabled | disabled | disabled | disabled |
| ThinkPad T14 Gen1 (i5 10310U) | disabled | disabled | not adjustable | disabled |
| Book XP14 Gen12 (i7 1165G7) | disabled | disabled | disabled | not adjustable |
| Katana GF76 11UE (i7 11800H) | disabled | disabled | not adjustable | disabled |
| ThinkPad T14 Gen3 (i7 1260P) | disabled | ENABLED | disabled | disabled |
| ThinkPad L14 Gen3 (i7 1265U) | disabled | disabled | not adjustable | disabled |
| IdeaPad 5 Pro 16IAH7 (i7 12700H) | disabled | max perf. | not adjustable | not adjustable |
| ThinkStation P360 Tiny (i7 12700T) | disabled | disabled | not adjustable | disabled |
| InfinityBook Pro Gen8 (i7 13620H) | disabled | not adjustable | not adjustable | not adjustable |
| InfinityBook Pro Gen8 (i7 13700H) | not adjustable | not adjustable | not adjustable | not adjustable |
| custom PC (i7 13700K) | disabled | disabled | disabled | not adjustable |
| Gemini Gen2 (i9 13900HX) | disabled | disabled | not adjustable | not adjustable |
| System | force clock speed to base clock speed | SpeedStep and Power Mgmt disabled |
|---|---|---|
| custom PC (i7 4790K) | failed | not adjustable |
| ESPRIMO D757 (i3 6100) | failed | not adjustable |
| NUC (i5 7300U) | P0 2600 MHz | not adjustable |
| ThinkPad T480s (i5 8350U) | failed | disabled |
| Yoga 730 15IWL (i7 8565U) | P3 1800 MHz | not adjustable |
| ThinkPad X390 Yoga (i7 8665U) | failed | disabled |
| OMEN 17 CB0XXX(i7 9750H) | P1 2600 MHz | not adjustable |
| ThinkPad P1 Gen2 (i7 9850H) | failed | disabled |
| custom PC (i9 9900K) | failed | disabled |
| ThinkPad T14 Gen1 (i5 10310U) | failed | disabled |
| Book XP14 Gen12 (i7 1165G7) | P0 2800 MHz | not adjustable |
| Katana GF76 11UE (i7 11800H) | failed | disabled |
| ThinkPad T14 Gen3 (i7 1260P) | P3 2300 MHz | ENABLED |
| ThinkPad L14 Gen3 (i7 1265U) | failed | disabled |
| IdeaPad 5 Pro 16IAH7 (i7 12700H) | P3 2500 MHz | not adjustable |
| ThinkStation P360 Tiny (i7 12700T) | P0 1400 MHz | disabled |
| InfinityBook Pro Gen8 (i7 13620H) | P3 2700 MHz | not adjustable |
| InfinityBook Pro Gen8 (i7 13700H) | P3 2700 MHz | not adjustable |
| custom PC (i7 13700K) | P0 3400 MHz | not adjustable |
| Gemini Gen2 (i9 13900HX) | P0 2400 MHz | not adjustable |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).