3 ms·
It's more secure due to automatic address space layout randomization. In fact, it's both space layout and space content randomization-- each application/kernel
by aassddffasdf 8y ago
It's more secure due to automatic address space layout randomization. In fact, it's both space layout and space content randomization-- each application/kernel is unique.
- xj9 8y agoif your kernel is doing ASLR correctly, i'm not sure doing it again in each virtual kernel will meaningfully increase the entropy of the memory layout.
- aassddffasdf 8y agoThat's not the point. It's both ASLR and ACLR. ASLR is not enough for certain vulnerabilities when the attackers know which bits/content are present.
- aassddffasdf 8y agoAlso, there is no kernel but the unikernel itself in such systems. So no idea what you mean by again here.
- xj9 8y agothat would be true if the unikernel was running alone on bare metal, but the more likely case is that you are deploying multiple unikernels on top of some hypervisor. in the case of Xen, you will have linux or *bsd in dom0 which will probably have aslr enabled. so, when you launch your unikernel and do aslr you will be randomizing an already random memory layout. my point of contention is with the hypervisor+unikernel model. once you try to increase the tenant density of a particular piece of hardware with virtualization you lose most of the advantages of removing the os and re-introduce the complexity in a different way.