News

VMware Acquisition Points to New Focus on Security

VMware's senior product director explains how the company will use its Determina acquisition to bolster its security reputation.

Tue, May 06, 2008 — IDG News Service (San Francisco Bureau) — VMware says it's received a bad rap when it comes to security.

The company's problems started with a 2006 presentation at the Black Hat security conference by Joanna Rutkowska, CEO of Invisible Things Lab . Ironically, Rutkowska's "Blue Pill" talk had nothing to do with VMware . It was about creating undetectable malicious software using the virtualization technology built into microprocessors.

But nevertheless, VMware is the world's best-known virtualization company, so any questions about virtualization and security "naturally became a VMware problem," said Nand Mulchandani, the company's senior director for security products.

"Blue Pill kind of set things off, but unfortunately it set things off on the wrong foot," he said. Soon VMware was fielding questions from worried customers. "They escalated it to our team and they said, 'Oh my God, we're going to get attacked by Blue Pill. What do we do?'"

Mulchandani has been trying to get the message across that the Blue Pill CPU virtualization hack is not connected to VMware's software, which is widely used on data center servers to simultaneously run many copies of the operating system on a single computer.

It's one of several security messages that Mulchandani is trying to convey these days, as the company looks to repair its reputation in the security community while developing new products that will keep it one step ahead of rivals.

Critics say VMware must shoulder some of the blame for the Blue Pill confusion and that it harmed itself by attacking Blue Pill in company blog postings. "They took the easy route, which was to attack Joanna's research," said Tom Liston, a senior security consultant with Intelguardians Network Intelligence . "It was just a big brouhaha with VMware jumping in where they didn't belong."

The feud with Rutkowska flared up at a low point in the company's relationship with independent security researchers. Employees who had been working with researchers like Liston left, and by early 2007 the company had developed a reputation as being unresponsive to bug reports, something Mulchandani calls "Fortress VMware."

Mulchandani says the issue was simply that VMware didn't have the people in place to respond to the community. That changed, however, with the company's 2007 acquisition of intrusion-prevention software vendor Determina .

"With the Determina acquisition, a lot of the focus was on acquiring a team that had very fundamental and deep relationships with the security industry," said Mulchandani, formerly Determina's CEO. "We've really embraced the security community in a way we didn't before."

More from IT Drilldown « Back to Virtualization
CASE STUDY
Adventures in Managing Virtualization
Evan Jafa, CIO for First American, has already learned plenty about server virtualization during his data center revamp. But he says the greatest virtualization challenges for IT leaders are yet to come. Think process management, network provisioning, and IT organization makeovers. Full Story »

Loading...
Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization ABCs

Get up to speed on virtualization.

Learn More »
Virtualization MarketSpace
As data centers expand, the complexity of heterogeneous computing environments has become an impediment to efficient IT service delivery. Companies are looking for ways to address this complexity and improve the manageability of their data centers. Symantec can help you standardize your IT environment, systems management tools, and configurations to improve operational efficiency, reduce costs and complexity, and mitigate downtime.

Standardization Data Sheet
Today's enterprise data centers face the growing demand for the latest servers and additional storage capacity, as well as, the need for improved availability of their mission critical applications. Download »
 
SPONSORED LINKS
 

Evolve your data center on proven technology. The Brocade DCX.

Secure your virtual and physical environments with the same software.

Let's Get Virtual: A Look at Today's Server Virtualization Architectures

Webcast: Learn how to Simplify and Standardize Architecture

Transforming Virtualization into a Competitive Advantage

Webcast: Research insight into how organizations are using virtualization

A CIO's View of Server Virtualization

Windows Server 2008: To Upgrade or Not to Upgrade?

How to simplify mobility and reduce the cost of supporting mobile workers

Extending PCI Compliance to the Mobile Workforce

A proven approach to WAN optimization

Wireless Vulnerability Management: What It Means for Your Enterprise

The Best IT Strategy for a Company with Global Operations

Speed, agility, flexibility - The HP BladeSystem c-Class

The Business Value of Symantec Data Center Foundation Solutions

Webcast: Why standardizing your ECM platform is so critical to your success

The PCI Data Security Standard

The Universal Wireless Client: Simplify mobility and reduce the cost of supporting mobile workers

Compliance by the numbers- addressing requirements with online document management and collaboration technology

Video Series: IT Leaders discuss how IT is becoming part of the innovation cycle.

White Paper: WebMethods Business Process Management Suite

Survey and Whitepaper: Reducing IT Energy Drain for Business Gain

Top 10 Reasons to Go Green in IT

Gaining Transparency in IT Outsourcing

Case Study: Customer Integration Wins at Invitrogen

Eliminate network threats and downtime with Juniper Networks. View demo.

Choose a mobile device platform with familiar programs and simplified management

Green IT: Reducing Your Carbon Footprint with Citrix

Gene Kim's Practical Steps to Mitigate Virtualization Security Risks

Configuration Audit and Control for Virtualized Environments

Webcast: Building an Optimized Infrastructure

Survival of the Fittest: Disaster Recovery Design for the Data Center

Increase conversions on your site with the help of EV SSL.

Data Loss Prevention Starts at the Endpoint

Performance Brief: Mobile Application Acceleration

Strategies for centralizing data backup

Wide-area data services enable todays global enterprise

Discover PMI's credentials and career path tools

Symantec State of the Data Center Report

Getting the Most from your Data Protection Solution

Tripwire PCI DSS Solutions: Automated, Continuous Compliance

ITCi White Paper: Challenges and Opportunities of PCI

See why 93 of the Fortune Global 100 depend on Blue Coat.

Taking Document Automation to the Next Level

Research about the efficiencies created by different operating systems.

White Paper: Intel IT testing of select multi-core processors results

Architecting A Better Network Storage Solution

Experience the colorful side of business. Visit Frugalcolor.com.

Rethinking the Corporate Help Desk: Learn how to deliver anywhere, anytime incident response

Top 10 Misconceptions about Performance and Availability Monitoring

 
 
RESOURCE CENTER