upvote
The big thing for me is the liveness is completely gone or at least can be. In a regular box I can at least poke around at the facilities even if the process dies. I don’t think it’s impossible I just think it’s a hard problem I don’t see emphasized enough.
reply
I don't know if anything like this has been built, but I'd imagine you could have the hypervisor capture stack traces / log buffers / core dumps when a unikernel VM crashes.
reply
I'm not a security researcher but I know that VMs have been the tool of choice to step through malware execution for at least the past 15 years. I recall coming across ida extensions for it.
reply