Linux
From Wikipedia, the free encyclopedia
Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).
Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.
Rules
- Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
- No misinformation
- No NSFW content
- No hate speech, bigotry, etc
Related Communities
Community icon by Alpár-Etele Méder, licensed under CC BY 3.0
From the FAQ of Qubes OS (i.e. most secure desktop OS for general use):
"Why does Qubes use Xen instead of KVM or some other hypervisor?"
"In short: we believe the Xen architecture allows for the creation of more secure systems (i.e. with a much smaller TCB, which translates to a smaller attack surface). We discuss this in much greater depth in our Architecture Specification document."
Thanks!
Searching for "XenTCB" already brings a lot of useful results
- TCB
- breaking up Hypervisors into smaller parts
- Xen 4.11 release info
- TCB overview
- [scientific paper about some more stuff])https://link.springer.com/content/pdf/10.1007/978-3-319-11203-9_18.pdf)
- security in a commodity hypervisor
As KVM is part if the Linux kernel, I assume you'll have to look into kernel hardening instead, next to OS hardening. Hardware is also important to consider when talking about VM escaping. A CPU that supports better VM isolation features and encrypted memory
Thanks, that's a great idea and I'll keep CPU support in mind