While I entirely agree with you wrt the kernel, the separation and isolation bits they do is new and novel from a general purpose operating system's standpoint. Also, Xen really is a small microkernel that runs ontop of Linux, so their comments on the separation being more secure than if they used KVM actually do have merit. If you want something similar that actually is a different operating system, checkout the Muen Separation Kernel (which is pretty neat tech).