How to Find and Fix 10 Real Security Threats on Your Virtual Servers

VM Sprawl. Hypervisor holes. Rogue virtual machines. Network traffic gone bad. What are the biggest virtualization security risks now and how can you combat them? It's time to separate fact from fiction and get down to work.

PAGE 5

6. Watch How You Provision Storage

Some enterprises are over-provisioning storage on SANs today, says Wolf. It's not that you're provisioning too much storage overall; it's that you may be letting the wrong VM's share a part of the SAN, he says.

If you're working with VMotion, VMware's tool for moving VMs around, you're assigning some zoned storage in SANs. But you may want to make that storage assignment more granular, as you would in the physical world, Wolf advises. Looking forward, N-port ID virtualization—a technique that lets IT assign storage to just one VM—is an option worth investigating, Wolf says.

7. Ensure Good Isolation Across Network Segments

As enterprises go virtual, they shouldn't ignore security-related network traffic risks. But some of these risks can inadvertently be overlooked, especially if IT leaders fail to bring networking and security staffers to the table while doing virtualization planning. "A lot of organizations simply use performance as the metric of how to consolidate," Wolf says. (When evaluating which application servers to co-locate as VMs on one physical box, IT teams tend to first focus on how performance-hungry those application servers will be, since you want to avoid asking any one physical box to bear too much load.) "They forget because of security restrictions on network traffic that they shouldn't locate these VMs together," Wolf says.

For example, some CIOs are deciding not to allow any virtualized servers in the DMZ (also known as demilitarized zone, the subnetwork that houses external services to the Internet, like e-commerce servers, adding a buffer between the Net and the LAN).

If you do have some VMs in the DMZ, you may want them on physically separate network segments from some of your other systems, say a critical Oracle database server, Wolf says.

At Arch Coal, the IT team thought about the DMZ from the start, Abbene says.

They've deployed virtual servers on the internal LAN but nowhere public facing. "That was a key early decision," Abbene says. For example, the company has some secure FTP servers and some servers doing lightweight electronic commerce in the DMZ; it has no plans to introduce VMs there, he says.

8. Worry About Switches

When is a switch not a switch? "Some virtual switches behave like a hub today: Every port is mirrored to all the other ports on the virtual switch," Burton Group's Wolf says. Microsoft Virtual Server, in particular today, presents this problem, Wolf says. VMware's ESX Sserver does not, nor does Citrix XenServer. "People hear the term 'switch' and think isolation exists. It really varies by vendor," Wolf says.

Microsoft has said the switch issue will be addressed in Microsoft's upcoming Viridian server virtualization software product, Wolf adds.

Loading...
Virtualization Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization ABCs

Get up to speed on virtualization.

Learn More »
Virtualization MarketSpace
MarketSpace White Papers
HP and VMware: Virtualization to consolidate server resources for maximum efficiency
Virtualization enables proven cost savings and efficiencies. Now you can tap that power by consolidating multiple applications and heterogeneous operating systems on a single server... Learn more »
Gartner Research: U.S. Data Centers
According to Gartner, the majority of existing US datacenters have not been designed to handle future energy demands. Strategic decisions, including the implementation of virtualization, must be made quickly... Learn more »
Gartner Research: How IT Management Can "Green" the Data Center
Datacenters consume large amounts of energy, so it is imperative that IT management establishes energy efficiency goals and an integrated approach to energy-saving initiatives... Learn more »
 
SPONSORED LINKS
 

Stories of real businesses that Virtualized their IT environments

Consolidation: Just the Starting Point for Virtualization

Security and Trust: The Backbone of Doing Business over the Internet

Prudential Financial Protects its Brand with Symantec

Put Enterprise Communications on Autopilot

Portfolio Management for Effective IT Governance

Unify and Conquer: The Benefits of Unified Communications.

Data Center Asset Planning - Regaining Control of the Data Center

Quest Authentication Services: Simplify Identity Management

Turn Information into a Competitive Advantage

Top 10 Ways to Protect Against Web Threats

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

The Benefits of Data Deduplication for Data Protection in the Enterprise

Reap the Benefits of Unified Communications

Renowned Engineering Institution Chooses AMD Processor-Based Servers

New research validates telepresence solutions.

Heinz Uses a Wireless, Automated, Auditing process on BlackBerry® devices

Network Immunity Manager Video

Keep proven data center technology. Evolve with Brocade

Motorola AirDefense can identify and exterminate your rogue APs. Learn more

CA's IT Security centralizes your identity management to turn security into a proactive, business-building tool

Efficient - Flexible - Compliant

Is there a secret to Sharepoint® Security? www.SharePointSecured.com

Request a Novell/Microsoft deployment workshop

Keep your valued customers through tight business integration - it's a lot easier than you think

Virtualization: Simplify. Automate. Lower Costs.

Improve delivery of product information to customers.

7 Requirements of Data Loss Prevention

Learn About the Features of the Google Universal Search Solution.

Mission Impossible: Building the Right Project Metrics

Project Portfolio Management - Boost the Value of IT

Telepresence - A Realistic Solution Connecting a Global Workforce

Integrating ActiveRoles With IBM Tivoli Identity Manager 5.0

Quest Authentication and IBM Tivoli Identity Management

HP Webcast: Transforming the Data Center

How End-User Monitoring Can Help You Improve Customer Satisfaction

Destination: Intelligent Data Center Automation

Protecting Data in a Highly Networked World

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

Sheriff's Office Uses PocketCop to Access Police Databases from BlackBerry® Smartphones

The BlackBerry Solution Adds Significant Benefit to Toshiba

HP Puts Its Disaster-tolerant Capabilities to the Test

Industry Analyst Report: Top Hosted Exchange Vendors in 2008

Log onto Hitachi True Stories, films inspired by the next great achievement

CA delivers deeper insight into your assets, resources, projects & services so you can make more informed IT decisions

Manage your IT more effectively

Request a Novell/Microsoft deployment workshop and kit

Request a Novell/Microsoft deployment kit

Let Hubspan's managed service tackle your business integration challenge so you can focus on your core business

 
 
RESOURCE CENTER