3 ms·
Did you know that AWS uses their own version of Xen? Xen was actually written with security in mind, they push as much of the features and driver code out of t
by click170 11y ago
Did you know that AWS uses their own version of Xen?
Xen was actually written with security in mind, they push as much of the features and driver code out of the hypervisor and onto Dom0 as possible to minimize the attack surface in the hypervisor itself.
Source - The Definitive Guide To Xen - 2007.
- cbd1984 11y agoIs it possible to tell whether you're running under Xen? Because that should be considered a security hole. Knowing the attack surface is there is, in this context, a security bug in and of itself, because it implies there is already an attack, or an attack is forthcoming. Unless it's possible to run an unmodified Xen as a guest under Xen, the project is incomplete.
- AReallyGoodName 11y agoFor PV it's quite easy. 'uname -a' is currently straight up telling me i'm on the el5xen PV kernel. If the kernel itself doesn't just straight up say it's a kernel designed to work under Xen the drivers used to work with the virtualization will give it away. Right down to the version if you care to dig deep enough and compare builds.
- cthalupa 11y agoIt's trivial on HVM as well http://www.brendangregg.com/blog/2014-05-09/xen-feature-detection.html http://www.brendangregg.com/blog/2014-05-09/xen-feature-dete...