How to Find and Fix 10 Real Security Threats on Your Virtual Servers

VM Sprawl. Hypervisor holes. Rogue virtual machines. Network traffic gone bad. What are the biggest virtualization security risks now and how can you combat them? It's time to separate fact from fiction and get down to work.

PAGE 6

9. Monitor for "Rogue" VMs on Desktops and Laptops

Servers are not your only worry. "The greatest threat is on the client side—rogue VMs," Burton Group's Wolf says. What's a rogue VM? Remember, Wolf says, your users can download and use a free program like VMware Player, which lets a desktop or laptop PC user run any VM created by VMware Workstation, Server or ESX Server.

Many users now like to use VMs on a desktop or laptop to separate pieces of work, or work and home-related activities. Some people use VMware Player to run multiple OSes on the machine; say using Linux as a base OS but creating a VM for running Windows apps. (IT teams also can also use VM Player to evaluate virtual appliances—software products shipping configured as a VM.)

"Often times, those VMs are not even at the right patch level," Wolf says. "Those systems get exposed to your network. And now all of these unmanaged OSes can float around."

"There's a lot of risk you're adding there," Wolf says, noting that the machines running rogue VMs could spread viruses—or worse—to your physical network. For example, he says, it would be very easy for someone to load up a DHCP server to give out fake IP addresses. That's effectively a denial of service attack, he notes. At the very least, you're going to waste IT resources trying to track down the problem, he says. "It may even be simple user error introducing services to the production network."

How can you prevent against rogue VMs? You should have controls around who gets VMware Workstation, for starters (since it's needed to create the VMs). IT can also use a group security policy to prevent certain executables from running, such as those needed to install VM player, Wolf notes. Another option: Do periodic auditing of user hard drives. "You want to look for machines with VMs and flag them for follow up by IT," he says.

Has this become yet another point of contention between users and IT, where savvy users want to use VMs at work the same as they're doing at home? Not yet, Wolf says. "IT departments for the most part have ignored it," Wolf says.

If you do want to allow VMs on user machines, tools such as VMware's Lab Manager and other management tools can help IT control and monitor those VMs, he notes.

10. Remember Virtualization Security at Budget Planning Time

"Make sure to allocate budget for virtualization security and management," IDC's Elliott says. You may not need to break it out in your security budget, Arch Coal's Abbene notes, but your security budget overall had better have enough funds for it.

Also, be careful of security costs as you do virtualization ROI calculations. "You may not see a reduced spend in security," just by virtualizing more and more servers, Hoff notes, because you will need to apply some of your existing security tools to every VM that you create. If you don't anticipate this expense, it could eat into your ROI.

According to Gartner, it's a common mistake right now. Through 2009, some 90 percent of virtualization deployments will have unanticipated costs, such as security costs, affecting ROI, according to a presentation by Gartner VP Neil MacDonald at Gartner's October 2007 Symposium/ITxpo.

Loading...
Virtualization Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization ABCs

Get up to speed on virtualization.

Learn More »
Virtualization MarketSpace
MarketSpace White Papers
HP and VMware: Virtualization to consolidate server resources for maximum efficiency
Virtualization enables proven cost savings and efficiencies. Now you can tap that power by consolidating multiple applications and heterogeneous operating systems on a single server... Learn more »
Gartner Paper: U.S. Data Centers
According to Gartner, the majority of existing US datacenters have not been designed to handle future energy demands. Strategic decisions, including the implementation of virtualization, must be made quickly... Learn more »
Gartner Paper: How IT Management Can "Green" the Data Center
Datacenters consume large amounts of energy, so it is imperative that IT management establishes energy efficiency goals and an integrated approach to energy-saving initiatives... Learn more »
 
SPONSORED LINKS
 

Consolidation: Just the Starting Point for Virtualization

Protecting Data in a Highly Networked World

Maximizing Site Visitor Trust Using Extended Validation SSL

Standalone Server vs. Open Source Toolkits

Getting Off on the Right Foot: Avoiding Common Master Data Management False Starts

The Challenge of Network Access Control -- Is a Managed Service the Answer?

Renowned Engineering Institution Chooses AMD Processor-Based Servers

New research validates telepresence solutions.

Configuration Assessment: Choosing the Right Solution

They Can't Steal What You Don't Have: Smart Security Choices for Mobile Workers

How to Calculate the ROI of Remote Support

31 Best Practices for the Service Desk

Unified Communications Software: The Death of VoIP?

Unify and Conquer: The Benefits of Unified Communications.

Heinz Uses a Wireless, Automated, Auditing process on BlackBerry® devices

Webcast: Solutions to the Toughest IT Challenges in Remote Offices

Network Immunity Manager Video

Dell Latitude: Battery life up to 19 hours. Learn more

Video: 21st Century Networking for a 12th Century Castle

Speed, agility, flexibility - The HP BladeSystem c-Class

Learn about the software-based VoIP solution from Microsoft

Microsoft System Center - Designed For Big

Accelerating ITIL at the Service Desk

Putting Open source to the test

Webcast: Roundtable discusses industry trends for Enterprise Content Management

File Integrity Monitoring: Secure Your Virtual & Physical IT Environments

How the Mac is Becoming an IT Standard in the Enterprise

Storage Efficiency: The Key to Green Storage Operation

Oracle Database 11g: Real Application Testing & Manageability

Reap the Benefits of Unified Communications

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

Optimizing Infrastructure Control

Effective Security with a Continuous Approach to ISO 27001 Compliance

Best Practices for Providing Secure and Cost-Effective Remote Access

How Does Your IT Help Desk Measure Up?

White Paper: Businesses Thrive by Unifying Business Communications

Getting Network Management Right: A Gartner IT briefing

Sheriff's Office Uses PocketCop to Access Police Databases from BlackBerry® Smartphones

The BlackBerry Solution Adds Significant Benefit to Toshiba

Write an RFP for Master Data Management: 10 Common Mistakes to Avoid

HP Puts Its Disaster-tolerant Capabilities to the Test

SOA Educational Library at the TIBCO SOA Resource Center

TDWI Report shows strong validation for investing in predictive analytics

Cost-Effective Data Center 1U Server Solutions

Secure your virtual and physical environments with the same software

GET YOUR VoIP ONTM! Win 2 Years of Hosted VoIP from Cypress. $100,000 retail value. Enter today!

Virtual Support Technology Delivers Quantifiable Gains in Productivity and Performance

Weigh the trade-offs between outsourcing communications and keeping it on-premise.

Stimulating Innovation: Meeting IT's New Mission

 
 
RESOURCE CENTER