3 ms·
With containers the entire surface area of the kernel is available to attack (syscalls). With a VM the surface is restricted to the VMM and KVM. This is an ove
by rogers18445 4y ago
With containers the entire surface area of the kernel is available to attack (syscalls). With a VM the surface is restricted to the VMM and KVM.
This is an oversimplification, there may be other protocols that are passed through or utilized, they would add to the surface.