Virtualization's Secret Security Threats

Hear what the U.S. National Security Agency thinks about the pros and cons of virtualization, inside and outside its IT department.

PAGE 2

These new chips will have what AMD's McDowell calls a "device exclusion vector" that can authorize or block hardware access to VMs, as well as create a chain of permissions that flow from one device to another, so OS and hypervisor developers can control not only what hardware can do what, but also what flows among hardware devices are permitted. McDowell expects this approach to prevent the subsystem-as-spy problem that both it and the NSA identified.

Virtual Layers Add Security

While virtualization is used commercially to have multiple operating systems run on one machine (to get more usage from physical servers, to run Windows on Macs, and to easily set up testbed environments) its origins trace back to a military security need. In fact, the VMware technology that popularized virtualization is a spin-off of Defense Department-sponsored research done at Stanford University; the military saw early promise in virtual machines to encapsulate networks and desktops from outside threats, resulting in an NSA-created OS called NetTop that in 2001 did for Linux what products such as Parallels Desktop and VMware Desktop do today: provide separate VMs that can't affect each other on one box.

Now the NSA sees virtualization protecting systems in a new layering approach, Simard said. The idea is to have an independent layer handle security, so even if an OS has security flaws, a separate layer that the OS can't compromise handles security threats such as viruses and worms or implements firewalls. Simard said it's inevitable that PC operating systems will have security holes: "The PC platform is a very feature-rich platform, and being feature-rich gets it into trouble."

The NSA, working with General Dynamics and IBM, has developed the first version of this technology, which it calls the High Assurance Platform workstation, for the U.S. Special Operations Command, using VMware, Novell SuSE Linux, and Red Hat Linux, Simard said.

"I believe strongly in doing antivirus and firewalling in isolation outside the OS," said AMD's McDowell. But Simard is concerned that this layered approach could compromise security if poorly implemented in commercial systems. The reason: If the security layer is compromised, such as through poor design, then an intruder now has access to all the VMs on the system. McDowell agreed with that concern, saying that such a layered approach can't replace security at the OS and network; instead it must supplement those components' security. He also noted that applications are the most common route for vulnerabilities to find their way into an OS, so they too need to have their own protection mechanisms.

Loading...
Virtualization Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization ABCs

Get up to speed on virtualization.

Learn More »
Virtualization MarketSpace
MarketSpace White Papers
HP and VMware: Virtualization to consolidate server resources for maximum efficiency
Virtualization enables proven cost savings and efficiencies. Now you can tap that power by consolidating multiple applications and heterogeneous operating systems on a single server... Learn more »
Gartner Paper: U.S. Data Centers
According to Gartner, the majority of existing US datacenters have not been designed to handle future energy demands. Strategic decisions, including the implementation of virtualization, must be made quickly... Learn more »
Gartner Paper: How IT Management Can "Green" the Data Center
Datacenters consume large amounts of energy, so it is imperative that IT management establishes energy efficiency goals and an integrated approach to energy-saving initiatives... Learn more »
 
SPONSORED LINKS
 

Consolidation: Just the Starting Point for Virtualization

Getting in Compliance with Government Data Regulations

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

The Benefits of Data Deduplication for Data Protection in the Enterprise

File Integrity Monitoring: Secure Your Virtual & Physical IT Environments

How the Mac is Becoming an IT Standard in the Enterprise

Storage Efficiency: The Key to Green Storage Operation

Oracle Database 11g: Real Application Testing & Manageability

Reap the Benefits of Unified Communications

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

Optimizing Infrastructure Control

Effective Security with a Continuous Approach to ISO 27001 Compliance

Best Practices for Providing Secure and Cost-Effective Remote Access

How Does Your IT Help Desk Measure Up?

White Paper: Businesses Thrive by Unifying Business Communications

Sheriff's Office Uses PocketCop to Access Police Databases from BlackBerry® Smartphones

The BlackBerry Solution Adds Significant Benefit to Toshiba

Network Immunity Manager Video

Spam-proof your business with Google's hosted security solutions

Global Crossing is the most viable alternative for voice, video and data

Plan better, manage better

Dell Latitude: Battery life up to 19 hours. Learn more

Video: 21st Century Networking for a 12th Century Castle

Speed, agility, flexibility - The HP BladeSystem c-Class

The Latest Advancements in SSL Technology

How to Offer the Strongest SSL Encryption

Destination: Intelligent Data Center Automation

Build up or Tear down? See how UC makes sense with Nortel. Calculate your UC ROI

Protecting Data in a Highly Networked World

Maximizing Site Visitor Trust Using Extended Validation SSL

Standalone Server vs. Open Source Toolkits

Getting Off on the Right Foot: Avoiding Common Master Data Management False Starts

The Challenge of Network Access Control -- Is a Managed Service the Answer?

Renowned Engineering Institution Chooses AMD Processor-Based Servers

New research validates telepresence solutions.

Configuration Assessment: Choosing the Right Solution

They Can't Steal What You Don't Have: Smart Security Choices for Mobile Workers

How to Calculate the ROI of Remote Support

31 Best Practices for the Service Desk

Unified Communications Software: The Death of VoIP?

Heinz Uses a Wireless, Automated, Auditing process on BlackBerry® devices

Write an RFP for Master Data Management: 10 Common Mistakes to Avoid

HP Puts Its Disaster-tolerant Capabilities to the Test

Compuware.com - See how we make IT rock around the world

CA delivers deeper insight into your assets, resources, projects & services so you can make more informed IT decisions

Discover PMI's credentials and career path tools

SOA Educational Library at the TIBCO SOA Resource Center

TDWI Report shows strong validation for investing in predictive analytics

Learn about the software-based VoIP solution from Microsoft

 
 
RESOURCE CENTER