Future Threats to Virtualization Security: Fact vs. Fiction

Who will be the TJX of virtualization security mistakes? No one knows yet, but one thing's certain: If you're a CIO, it better not be your company.

Wed, November 14, 2007CIO "There hasn’t been a significant security breach in virtualization, not a public one," says IDC analyst Stephen Elliott. "At some point, you have to figure it's a matter of time."

IT leaders must deal with virtualization security the same way they've dealt with numerous other threats: budgeting, planning, tools, process and vigilance. But those IT leaders must also be able to separate the real threats from the theoretical ones, and that's not always easy right now.

What's on the virtualization threat horizon and is discussed in security labs but not appearing in real-life data centers yet?

For starters, there's been a lot of talk online and at some conferences regarding the possibility of hypervisor malware and hypervisor weaknesses. This past summer, a security consulting firm called Intelguardians Network Intelligence argued that it may be possible for a hacker to "break out" of a VM's guest operating system and into the host OS of a server. This invites the possibility of installing rootkits and other malware, Intelguardians argues.

Some security researchers discuss the possibility of a "Blue Pill" attack, using a virtual rootkit akin to the one created by security researcher Joanna Rutkowska. This kind of rootkit, the theory goes, can hide in the hypervisor and away from the vision of today's security tools.

Should you worry about these theoretical threats yet? Just how secure is a hypervisor?

"Blue Pill was really targeted as a Windows Vista exploit and never really materialized," says Burton Group's Wolf. "There's not been a significant threat yet." As for the hypervisor threats, he says, "I think the threats there are a bit exaggerated. The key is central monitoring and updating."

More troubling perhaps, says security researcher Chris Hoff: Given today's virtualization and security tools, IT has real trouble seeing into the traffic running between VMs. "Today we've deployed security sprinkled in boxes throughout the network," Hoff says. "But traffic patterns may be such now that trouble doesn’t even hit the network." IT very much needs tools to be able to peek into that inter-VM traffic, Hoff says. "The network and security guys have lost precious visibility," he says.

Another more practical and immediate problem: Separation of duties among IT personnel can radically change in a virtualized environment, Hoff says, as access to more VMs gets loaded into management consoles. That's the kind of security issue a CIO should worry about before worrying about Blue Pill, he says.

Loading...
Data Center MarketSpace
White Papers
5 Tips for Data Loss Prevention Solutions
RSA® The Security Division of EMC has identified 5 key considerations to help organizations simplify the evaluation process for selecting a DLP solution that is right for their business. Learn more »
Power Considerations for Virtualized IT Environments
This paper describes some of power challenges related to virtualization - and the readily available technologies to address them. Learn more »
The Evolutionary Stages of the Data Center
How to avoid unplanned obsolescence in the power distribution infrastructure. Learn more »
Webcasts
 
SPONSORED LINKS
 

Developing A Dynamic, Real-Time IT Infrastructure

Learn about the VMware vSphere (TM) & Intel (R) Xeon (R) Processor 5500 Series

Bottom-Line Benefits of Virtualization

White Paper: The Building Blocks for Cloud Computing

New technology that addresses challenges organizations are facing.

Seven Ways ITIL Can Help You in an Economic Downturn

Maximizing the Business Value of the PC Infrastructure

Communications and Collaboration Needs at Business Organizations

Using Open Source to Deploy Web Applications

Mid-Sized Company CIO Community: infoBOOM!

Enterprise PBX Comparison Guide

Top-line Performance that's Bottom-line Efficient

Accenture: Outsourcing for uncertain times. Click to learn more.

White Paper: 8 Key Ingredients to Building an Internal Cloud

Building the Virtualized Enterprise with VMware Infrastructure

Top 10 Business and IT Drivers for the Wealth Management Sector

Oracle's Application Grid Technical Demo

Next-Generation Application Servers and Infrastructure

Application Infrastructure at Enterprise Organizations

Achieving Business Agility with Application Grid

Learn about The Information Technology Infrastructure Library.

Achieving Pervasive Performance Management

Automating the Generation and Secure Distribution of Excel Reports

Reduce risk, gain agility. See how Progress can help your business.

Improve ROI, lower TCO and reduce energy consumption.

Getting Value from Outdated Networking Equipment

Read about virtualization and consolidation effort best practices

Data Center Optimization: Three Key Strategies

A CIO Executive Guide: Cloud Computing Looms Big on the Horizon

Taking the Service Desk to the Next Level

Why Data Loss is Increasing--and What You Can Do About It

Data Loss Prevention: A Better Way to Approach Security

Learn how to managing client systems in the enterprise.

Cloud Computing: Read about VMware's compelling vision & set of products

Enterprise PBX Buyer's Guide

Secondary Market Primer: Your Network at Half Price

Accenture IT Consulting: Logical meets technological. More . . .

Stop Application Fraud at the Source with Device Reputation

Learn how a virtualized enterprise can help your company reduce costs

Why Isn't Server Virtualization Saving Us More?

8 Key Ingredients to Building an Internal Cloud

Oracle WebLogic Server Technical Demo

Data Grids and Service-Oriented Architecture

Achieving the Impossible: Unlimited Application Scalability

A Middleware Foundation for Application Grid

Tips for successful virtualization management.

Smart Decisions: The Role of Key Performance Indicators

Gartner Shares Predictions for 2009

64-page prescriptive guide to security, compliance, and IT operations.

Get Google Enterprise Search for your business information.

 
 
RESOURCE CENTER