Virtualization and Cloud Advisor

Expert analysis and advice on server virtualization technologies, deployments and management.

RSS
All Posts | RSS

Our blogger: Bernard Golden is CEO of consulting firm HyperStratus, which specializes in virtualization, cloud computing and related issues. He is also the author of "Virtualization for Dummies," the best-selling book on virtualization to date.

Wed, July 02, 2008

CISecurity Guide to VMware Security Falls Far Short

By Edward L. Haletky

Keywords: VMware, Security, Virtual Machines, CISecurity

I've written before about the lack of good tools and guides to security in virtual infrastructures.

The first widely used guide, the CISecurity VMware ESX Security Benchmark, contains a list of tasks to complete including the shell code to implement most of them. Unfortunately it is not as complete as I would like.

There are two benchmarks from CISecurity, one for VMware ESX and the other is for VMs.

The VM Benchmark is much too generic to be of much use. The VMware ESX edition contains settings and other data that are VM specific, rather than focusing on VMware ESX.

Unfortunately, the document includes only a few of the isolation tool settings; there are many many more that will improve security.

All but a few steps written in the benchmark are about the service console.

While it is important to protect the service console that is not the be-all and end-all of security.

Nowhere in the benchmark does it explain how the vmkernel itself can be protected. It also falls short in ways to limit information leakage from access to the SC, and how to prevent this.

Nor does it explain how the vmkernel protects itself. It assumes—as do many people—that the hypervisor is secure. This is the same as assuming that your firmware is above reproach, despite the availability of root kits that live just fine within firmware routines.

While the document does delve into several ESX specific issues, vSwitch Security options, and other virtual network concerns, it falls short of true understanding of this critical area.Unless readers fully understand the intricacies of hypervisor security, they will be missing some aspect of security.

For example, the benchmark states that iSCSI is a clear-text protocol and that the CHAP protocol should be used as part of authentication to keep usernames and passwords from being transmitted across the network in the clear.

But it fails to mention that NFS and Fibre Channel-SAN are also clear text protocols and should be protected.

It does mention that IPsec is not natively supported by VMware ESX. But does not discuss how this really makes a difference?

iSCSI for example supports IPsec only if devices at both ends of a communication link support it. Nor does the document mention that the VMware Consolidated Backup (VCB) Proxy Server, if in use, could become a backdoor to your VM data.

It is also missing information about the data paths used to manage the system. Specifically it is missing critical information about weaknesses in WebAccess for administration. There is missing information about the weak SSL certificates in use on some versions of ESX or how to remediate this.

Loading...
Virtualization Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization ABCs

Get up to speed on virtualization.

Learn More »
Virtualization MarketSpace
White Papers
Learn how to address key cloud computing challenges
Learn how your organization can face the challenges of: lack of interoperability, security, compliance and application compatibility. Learn more »
VMware: Clearing the fog, a look into the Clouds
Read about VMware's compelling vision & set of products that can help clarify all of the confusion surrounding Cloud Computing. Learn more »
Cloud Computing: A fundamentally new way to deploy IT services
Learn how the VMware vCloud initiative enables you to move to the cloud how you want, when you want, and as much as you want. Learn more »
Calculate Your Specific Potential Virtualization Savings
Discover how organizations are reducing operational costs, and improving efficiency and availability. Learn more »
Forecast: Cloud Computing Looms Big on the Horizon
Read this Executive Guide to learn more about what IT leaders are saying about "Cloud Computing". This is one time when it makes good, practical business sense to have your head in the clouds. Learn more »
 
SPONSORED LINKS
 

Developing A Dynamic, Real-Time IT Infrastructure

Mid-Sized Company CIO Community: infoBOOM!

Read about virtualization and consolidation effort best practices

Building the Virtualized Enterprise with VMware Infrastructure

8 Key Ingredients to Building an Internal Cloud

White Paper: The Building Blocks for Cloud Computing

Taking the Service Desk to the Next Level

Why Data Loss is Increasing--and What You Can Do About It

Data Loss Prevention: A Better Way to Approach Security

Learn how to managing client systems in the enterprise.

Enterprise PBX Buyer's Guide

Secondary Market Primer: Your Network at Half Price

Losing Ground: 2009 TMT Global Security Survey

Accenture IT Consulting: Logical meets technological. More . . .

Stop Application Fraud at the Source with Device Reputation

Top 10 Business and IT Drivers for the Wealth Management Sector

Oracle's Application Grid Technical Demo

Next-Generation Application Servers and Infrastructure

Application Infrastructure at Enterprise Organizations

Achieving Business Agility with Application Grid

Learn about The Information Technology Infrastructure Library.

Achieving Pervasive Performance Management

Automating the Generation and Secure Distribution of Excel Reports

Introducing the new HP ProLiant G6 server family

Accenture: Outsourcing for Competitive Advantage. More...

Cloud Computing: Read about VMware's compelling vision & set of products

White Paper: 8 Key Ingredients to Building an Internal Cloud

Learn how a virtualized enterprise can help your company reduce costs

Why Isn't Server Virtualization Saving Us More?

Bottom-Line Benefits of Virtualization

A CIO Executive Guide: Cloud Computing Looms Big on the Horizon

Seven Ways ITIL Can Help You in an Economic Downturn

Maximizing the Business Value of the PC Infrastructure

Communications and Collaboration Needs at Business Organizations

Using Open Source to Deploy Web Applications

Enterprise PBX Comparison Guide

Getting Value from Outdated Networking Equipment

Top-line Performance that's Bottom-line Efficient

Accenture: Outsourcing for uncertain times. Click to learn more.

Learn about the VMware vSphere (TM) & Intel (R) Xeon (R) Processor 5500 Series

Data Center Optimization: Three Key Strategies

Oracle WebLogic Server Technical Demo

Data Grids and Service-Oriented Architecture

Achieving the Impossible: Unlimited Application Scalability

A Middleware Foundation for Application Grid

Tips for successful virtualization management.

Smart Decisions: The Role of Key Performance Indicators

Gartner Shares Predictions for 2009

Accenture IT Consulting: Enabling high performance. More...

Top Five CIO Challenges

 
 
RESOURCE CENTER