Submission + - Study: Monolithic OS Design Is Flawed 1
Mike Bouma writes: As already reported by OSNews.com:
"Our results provide very strong evidence that operatingsystem
structure has a strong effect on security. 96% of critical
Linux exploits would not reach critical severity in a
microkernel-based system, 57% would be reduced to low
severity, the majority of which would be eliminated altogether
if the system was based on a verified microkernel.
Even without verification, a microkernel-based design alone
would completely prevent 29% of exploits.
Given the limited number of documented exploits, we
have to assume our results to have a statistical uncertainty
of about nine percentage points. Taking this into account,
the results remain strong. The conclusion is inevitable: From
the security point of view, the monolithic OS design is
flawed and a root cause of the majority of compromises. It
is time for the world to move to an OS structure appropriate
for 21st century security requirements."
"Our results provide very strong evidence that operatingsystem
structure has a strong effect on security. 96% of critical
Linux exploits would not reach critical severity in a
microkernel-based system, 57% would be reduced to low
severity, the majority of which would be eliminated altogether
if the system was based on a verified microkernel.
Even without verification, a microkernel-based design alone
would completely prevent 29% of exploits.
Given the limited number of documented exploits, we
have to assume our results to have a statistical uncertainty
of about nine percentage points. Taking this into account,
the results remain strong. The conclusion is inevitable: From
the security point of view, the monolithic OS design is
flawed and a root cause of the majority of compromises. It
is time for the world to move to an OS structure appropriate
for 21st century security requirements."