“Flierl explained that now with Solaris 11 a customer can create
a Zone that has its own dedicated network stack, complete with
firewall and isolation. The way the system has been implemented is
that it can leverage underlying hardware capabilities to provide
the virtualization without a performance hit.
From a cloud security perspective, there is a new Solaris 11
feature called, the immutable filesystem. With that, the filesystem
can be locked down so the user can’t accidentally or malicious make
any destructive changes to the filesystem.