Interop: People a big security threat to virtualization
- 19 September, 2008 08:53
- Comments
Interop New York 2008
While VMware this week is holding its own VMworld party in Las Vegas, attendees at Interop New York were told about the potential security risks of virtual environments, not the least of which are people.
At least for now, virtual servers, the hypervisors that oversee them, the management platforms that govern them and the IT staff that sets them up and runs them are all potential attack vectors, said Joshua Corman, principal security analyst for IBM/ISS. "Virtualization is a game changer for good and for bad," he said.
IT staffs under financial pressure to implement virtual servers may be overworked and lose the diligence to properly plan secure deployments Corman said. "Virtualization requires more discipline and enforcement of policies than before," he said.
Just as teams of server, network, security and application specialists typically oversee the deployment of traditional physical server farms, the same group should plan virtual rollouts, Corman said. But often, the security team is left out and server administrators may inherit the responsibility without the proper expertise. "Before there was a healthy balance of skill sets distributed well [among a variety of administrators]," he said.
This lack of balance generates unproductive finger pointing when things go awry and in some cases creates grabs for power as IT staff recognizes a shift in how work is being distributed. In either case, security can suffer, Corman said.
Meanwhile, virtual technology presents weak spots for attackers to take advantage of, he said. "Virtualization will set you back on your risk posture," he said. In particular, virtual environments are a "management nightmare" where each virtual machine may spawn another that could appear virtually anywhere. This makes instances of servers hard to find, let alone protect, he said, and this "server sprawl" can lead to catastrophic failures.
Individual virtual machines, called guests, can fall into vulnerable configuration due to a feature of virtualization that suspends them when they are not used, Corman said. When the applications these guests host are needed, they are brought back online, but in the meantime may have missed critical security updates and are left open to exploits.
Once a guest is taken over, it can contend for the available processing power within the same hardware and cause bottlenecks for applications on the other guests within the physical machine, he said.
- Bookmark this page
- Share this article
- Got more on this story? Email TechWorld
- Follow TechWorld on twitter
- Seven Steps to Effective Data Governance
- Teleworking made simple—and secure—with desktop virtualisation technology
- Maximise Software Cost Savings by License Reharvesting, Recycling & Applying Product Use Rights
- Transforming Your Business by Transforming Your Processes
- Securing SOA and Web Services with Oracle Enterprise Gateway
-
Coalition NBN better or worse?
-
CSIRO develops hands-free technology for mining repairs
-
Broadband Forum to improve IPTV performance with new spec
-
Amazon Web Services moves backups to cloud with new appliance
-
Callforfree.net.au offers free calls to 70 countries
-
Microsoft Office
-
Teach Yourself Visually Windows 7
-
Windows 7 for Dummies® Dvd+book Bundle
-
Excel 2007 All-In-One Desk Reference for Dummies
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Seniors for Dummies®
-
Office 2007 All-In-One Desk Reference for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 for Dummies








Comments
Post new comment