http://nksecur5aoxbew7x4t2jebk7ordomil3a4xubeamno76zexicppwhiad.onion/advanced-security-guide.html
Consider using a Linux OS which implements "Mandatory Access Control" when using virtual machines like libvirtd. Examples: Fedora: sVirt (SELinux), Ubuntu (AppArmor), or a more secure OS like Qubes OS. These provide additional protection in the unlikely event of a "virtual machine escape".