Is virtualisation a viable alternative to MAC ?
Is virtualisation a viable alternative to MAC ?
Posted Aug 2, 2010 2:34 UTC (Mon) by raven667 (subscriber, #5198)In reply to: Is virtualisation a viable alternative to MAC ? by haradats
Parent article: AppArmor set to be merged for 2.6.36
When it comes to the security of the whole system I would be far more concerned about the millions of network applications and OS exploits than buffer overflows in the handful of hypervisors which are in active use. A new exploit might be found on a common hypervisor platform, which is sufficient reason to put systems with radically different security zones on different hardware, but it probably isn't the biggest risk, probably not even in the top 10.
There is a lot more benefit to AppArmor, SELinux, TOMOYO, etc. in preventing applications with security vulnerabilities from accessing files, devices and system calls so that exploit payload isn't able to work.