Feature

Future Threats to Virtualization Security: Fact vs. Fiction

Who will be the TJX of virtualization security mistakes? No one knows yet, but one thing's certain: If you're a CIO, it better not be your company.

Wed, November 14, 2007CIO "There hasn’t been a significant security breach in virtualization, not a public one," says IDC analyst Stephen Elliott. "At some point, you have to figure it's a matter of time."

IT leaders must deal with virtualization security the same way they've dealt with numerous other threats: budgeting, planning, tools, process and vigilance. But those IT leaders must also be able to separate the real threats from the theoretical ones, and that's not always easy right now.

What's on the virtualization threat horizon and is discussed in security labs but not appearing in real-life data centers yet?

For starters, there's been a lot of talk online and at some conferences regarding the possibility of hypervisor malware and hypervisor weaknesses. This past summer, a security consulting firm called Intelguardians Network Intelligence argued that it may be possible for a hacker to "break out" of a VM's guest operating system and into the host OS of a server. This invites the possibility of installing rootkits and other malware, Intelguardians argues.

Some security researchers discuss the possibility of a "Blue Pill" attack, using a virtual rootkit akin to the one created by security researcher Joanna Rutkowska. This kind of rootkit, the theory goes, can hide in the hypervisor and away from the vision of today's security tools.

Should you worry about these theoretical threats yet? Just how secure is a hypervisor?

"Blue Pill was really targeted as a Windows Vista exploit and never really materialized," says Burton Group's Wolf. "There's not been a significant threat yet." As for the hypervisor threats, he says, "I think the threats there are a bit exaggerated. The key is central monitoring and updating."

More troubling perhaps, says security researcher Chris Hoff: Given today's virtualization and security tools, IT has real trouble seeing into the traffic running between VMs. "Today we've deployed security sprinkled in boxes throughout the network," Hoff says. "But traffic patterns may be such now that trouble doesn’t even hit the network." IT very much needs tools to be able to peek into that inter-VM traffic, Hoff says. "The network and security guys have lost precious visibility," he says.

Another more practical and immediate problem: Separation of duties among IT personnel can radically change in a virtualized environment, Hoff says, as access to more VMs gets loaded into management consoles. That's the kind of security issue a CIO should worry about before worrying about Blue Pill, he says.

Loading...
Virtualization Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization ABCs

Get up to speed on virtualization.

Learn More »
Virtualization MarketSpace
As data centers expand, the complexity of heterogeneous computing environments has become an impediment to efficient IT service delivery. Companies are looking for ways to address this complexity and improve the manageability of their data centers. Symantec can help you standardize your IT environment, systems management tools, and configurations to improve operational efficiency, reduce costs and complexity, and mitigate downtime.

Standardization Data Sheet
Today's enterprise data centers face the growing demand for the latest servers and additional storage capacity, as well as, the need for improved availability of their mission critical applications. Download »
 
SPONSORED LINKS
 

Choose a mobile device platform with familiar programs and simplified management

Green IT: Reducing Your Carbon Footprint with Citrix

White Paper: Juniper Networks Ethernet Switching Solutions Reduce Operational IT Expenses

Webcast: Learn why companies must invest in an agile network infrastructure

White Paper: Businesses Thrive by Unifying Business Communications

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

Renowned Engineering Institution Chooses AMD Processor-Based Servers

High-Definition: The Evolution of Video Conferencing

Managing Mobility: An IT Perspective

Unify and Conquer: The Benefits of Unified Communications.

Webcast: Increase traditional notebook computing ROI

Key challenges facing today's IT service and support

Sheriff's Office Uses PocketCop to Access Police Databases from BlackBerry® Smartphones

The BlackBerry Solution Adds Significant Benefit to Toshiba

The New Foundation of Storage: Xiotech's Intelligent Storage Element

Extending PCI Compliance to the Mobile Workforce

The Universal Wireless Client: Simplify mobility and reduce the cost of supporting mobile workers

Top 10 Reasons to Go Green in IT

Rethinking the Corporate Help Desk: Learn how to deliver anywhere, anytime incident response

Bringing Order and Security to your Mobile Workforce: Corporate Mobility Policy and Device Management

Network Immunity Manager Video

Cost-Effective Data Center 1U Server Solutions

Automate Business Processes - Try a Free Mashup Composer

Improve device management - Microsoft® System Center Mobile Device Manager

Explore the interactive whitepaper: Rightsizing Blades for the mid-market

Webcast: Building an Optimized Infrastructure

Transforming Virtualization into a Competitive Advantage

Juniper Networks is changing the economics of networking with a no-compromise, highperformance and service-oriented approach

Research about the efficiencies created by different operating systems.

Unified Communications Software: The Death of VoIP?

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

Seeing is Believing: The Value of Video Collaboration

Getting Network Management Right: A Gartner IT briefing

Demonstrating the Business Value of Mobile Device Management

Oracle Database 11g: Real Application Testing & Manageability

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

How to Manage the Mobile Work Environment

Heinz Uses a Wireless, Automated, Auditing process on BlackBerry® devices

Webcast: Solutions to the Toughest IT Challenges in Remote Offices

How to simplify mobility and reduce the cost of supporting mobile workers

Webcast: Why standardizing your ECM platform is so critical to your success

White Paper: WebMethods Business Process Management Suite

Gaining Transparency in IT Outsourcing

Top 10 Misconceptions about Performance and Availability Monitoring

Write an RFP for Master Data Management: 10 Common Mistakes to Avoid

HP Puts Its Disaster-tolerant Capabilities to the Test

Microsoft System Center - Designed For Big

Read Forrester's advice for deploying an enterprise mobile solution

Do the math-calculate the impact of mobile device deployment on your bottom line

Easily manage the Mac in your Enterprise

 
 
RESOURCE CENTER