[2016] Kernel Protection Using Hardware-Based Virtualization by Jun Nakajima & Sainath Grandhi
We propose that the Linux run in virtualization mode, activating hardware virtualization features to improve security and monitoring. Hardware enforced virtualization features can be used for hardening the kernel, by protecting key kernel data structures and locking the processor state when the processor is executing in guest mode. Security features from the latest processors can be added to virtual processors. Kernels running on platforms with processors from older generations are benefitted. For the bare-metal, we have added a thin hypervisor to the kernel, and we have extended KVM for guest kernels so that they can identify this capability as a CPU feature, become enlightened and work with the hypervisor to lock and monitor kernel resources and processor state. In this talk we will present the idea, its benefits and the work we have done in Linux/KVM. Sainath Grandhi Intel Work for Intel in Open Source Virtualization group. Work on Xen and KVM kernel feature enabling. Currently working on a project that is a solution to run containers with a hypervisor underneath to provide security and resource isolation. Jun Nakajima Intel Open Source Technology Center, Senior Principal Engineer San Francisco Bay Area Jun Nakajima is a Senior Principal Engineer leading open source virtualization and cloud projects, such as, KVM, Xen, and OpenStack at the Intel Open Source Technology Center. Jun has been working on various virtualization projects for almost a decade, and NFV is one of his ongoing projects. Jun presented a number of times at technical conferences, including KVM Forum, Xen Summit, and USENIX. He has over 20 years of experience with operating system internals and virtualization. Slides: http://www.linux-kvm.org/images/4/40/...
![[2016] LinuxCon: Real-Time KVM by Rik van Riel](https://i.ytimg.com/vi/o6H8PhtOWK8/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLBQOrhsrtinSfDEUOpMCIyU3oGrqQ)
[2016] LinuxCon: Real-Time KVM by Rik van Riel
![[2016] Keynote: KVM Status Report by Paolo Bonzini](https://i.ytimg.com/vi/eGLdht1r70M/hqdefault.jpg?sqp=-oaymwE9CNACELwBSFryq4qpAy8IARUAAAAAGAElAADIQj0AgKJDeAHwAQH4Af4JgALQBYoCDAgAEAEYciBWKC0wDw==&rs=AOn4CLAC3GJxVVqw2ObxM68CACTC0UxErA)
[2016] Keynote: KVM Status Report by Paolo Bonzini

Building the PERFECT Linux PC with Linus Torvalds
![[2016] Libvirt Admin API - A Different Kind of Management for libvirt by Erik Skultety](https://i.ytimg.com/vi/K7C4SZTwOfw/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLC5gEOmuKLqj4GB85D-v74UX6SKTg)
[2016] Libvirt Admin API - A Different Kind of Management for libvirt by Erik Skultety

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!
![Kubernetes Tutorial for Beginners [FULL COURSE in 4 Hours]](https://i.ytimg.com/vi/X48VuDVv0do/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLDNg7nINwKqigXGqrL80FN9YuTNGg)
Kubernetes Tutorial for Beginners [FULL COURSE in 4 Hours]

Will AI destroy the economy?

Inside Anthropic, the $965 Billion AI Juggernaut | The Circuit

Linux Full Course for Beginners | Learn Linux System Administration

How To Think SO CLEARLY People Assume You're A Genius

IT Fundamentals Course – Hardware, Cloud, DevOps, Networking, Security, Databases, DNS, Git, Linux

Why Aliens Would NEVER Invade Africa

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

Kali Linux Beginner Course - AI Era of Hacking (Part 1 of 3)

What do tech pioneers think about the AI revolution? - The Engineers, BBC World Service

Historian Timothy Snyder on ENDING Trump Nightmare FOR GOOD | PoliticsGirl

What to teach when AI writes the code | Rainer Stropek | TEDxLinz

6 Tips on Being a Successful Entrepreneur | John Mullins | TED

