|
|
|
|
|
by tscs37
3262 days ago
|
|
1) You are in Ring 0. There is no defense unless you reimplement a normal Kernel to run a process in Ring 3 along with the monitoring process and capabilities management... etc 2) No, the attacker is most likely there because of some bug in the app, once in the network, it becomes harder to stop the attacker infecting other instances. 3) Hypervisors are not perfect. There are known instances of people infecting the host through the hypervisor. |
|
2) The same applies to any application, not just unikernels.
3) I completely agree.