Black Hat Spotlights Virtualization, DNS Issues

Rushing to virtualize can create security problems for enterprise customers.

By Tim Greene , Robert McMillan , Ellen Messemer

CONNECTIONS
Blackt Hat
Cisco
Brocade
Fri, August 08, 2008Network World LAS VEGAS — The 12th Black Hat conference convened at Caesar’s Palace last week, where the 4,500 attendees (a 12.5 percent increase over last year) heard about the security problems that will plague virtualized environments, why Cisco routers are more of a hacker target than ever and a detailed explanation of DNS attacks.

Attendees also found a conference show floor that was dominated by vendor booths. The booths, once a rarity at the conference, are becoming more prevalent as vendors inject themselves into the Black Hat mix. While he didn’t apologize for their presence — and noting that vendor sponsorships are important to the financial success of the conference — Black Hat founder and director Jeff Moss did distance the content of the show from the sponsors. Presenters at the show briefings present vendor-neutral material chosen solely for its value to the security community, he said during his opening remarks.

Vendor booths aside, the audience was tuned to far more weighty topics, such as the security problems that will ultimately arise out of the industry’s headlong push into virtualizing everything.

Virtualization “will not save you money, it will cost you more,” and “virtualized security can seriously impact performance, resilience and scalability,” said Christopher Hoff, chief security architect at Unisys, in an impassioned presentation. Hoff argued the user community is being sweet-talked into virtualization by an industry unmindful of the security consequences.

“Over the next 12 to 18 months, there’s a very uncomfortable set of circumstances as every vendor rushes out to say we’ve virtualized,” said Hoff in his talk, entitled “The Four Horsemen of the Virtualization Apocalypse.”

Using strong language directed at the network industry, Hoff argued that “it’s getting real messy” as Cisco, Brocade, 3Leaf, Xsigo, among others gallop off toward virtualization of basic switching infrastructures. This is being done without a clear notion of what the security consequences are for enterprise customers accustomed to wholly different topologies that include technologies such as spanning tree and STP.

“A virtual switch is just a piece of code like a hypervisor,” said Hoff about the industry’s new direction. “It’s basically Layer 2 switching modules,” adding it means you’ve collapsed the network into “a single tier” and “it all boils down to three settings in a GUI.”

The virtual security — he called it “VirtSec” — that’s arising in the wake of anticipated changes is ushering in virtual appliances that will become the cornerstone for trying to replicate traditional defenses such as intrusion-prevention systems, antivirus and firewalls, Hoff said. But as security functions compete for virtual-machine resources, there will be a performance hit just as is seen in unified threat management (UTM) devices today that combine IPS, firewall and other functions, he said.

Loading...
Virtualization Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization ABCs

Get up to speed on virtualization.

Learn More »
Virtualization MarketSpace
MarketSpace White Papers
Twenty-to-One Consolidation on Intel Architecture: New Tools for Virtualization and Workload Management
Consolidation isn't easy—especially considering the costs and risks that come with bringing multiple applications and operating systems together on a single mainframe or proprietary platform... Learn more »
Building the Virtualized Enterprise with VMware Infrastructure
Many organizations struggle with their legacy IT infrastructures which are often plagued by high costs, slow response times and inconsistent management... Learn more »
TECHNOLOGY ASSESSMENT: The Impact of Virtualization Software on Operating Environments
Virtualization is a potential game-changer for modern computing. This IDC Technology Assessment discusses how virtualization technologies impact operating environments, now and in the future... Learn more »
Reducing Server Total Cost of Ownership with VMware Virtualization Software
Technology purchases are often quantified simply by hardware and software costs. But there's more to it. This TCO study takes a holistic view—considering soft dollars too, like ongoing maintenance and... Learn more »
 
SPONSORED LINKS
 

Learn how to leverage virtualization for a 74% savings in TCO.

Find out how you can affordably consolidate applications with VMware.

Discover what you need to consider when evaluating virtualization.

Save with 0% Lease Offer on HP Servers and Storage

Find out how to manage virtualization's risks and reap the rewards.

Conquer the realities of managing virtualization

Expand High-Performance Computing (HPC) Capabilities

Power the Platform of Choice for Virtualization in the Enterprise

Virtualization: Simplify. Automate. Lower Costs.

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

How RFID Improves Data Center Efficiency

Determine the ROI of Web Application Acceleration Managed Services

Achieve a 50:1 Data Deduplication Ratio

Remote Infrastructure Management - What Your Peers are Thinking

Ponemon Study: How Much Does a Data Breach "Cost"?

Data Protection: Challenges for the Traveling User

Optimizing Infrastructure Control

File Integrity Monitoring: Secure Your Virtual and Physical IT Environments

Effective Security with a Continuous Approach to ISO 27001 Compliance

Leading university calls on Nokia for mobile unified communications.

Mobility is Growing: Survey Shows Why CIOs are Concerned

Learn what it takes to build a holistic digital collaboration platform

The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

Customer Insight Yields Sales, Marketing Gains

7 Requirements of Data Loss Prevention

Find out why IDC thinks virtualization is changing operating environments.

Explore the impact virtualization can have on your bottom-line.

ESG Research on Server and Storage Virtualization

Get help navigating the management challenges of virtualization.

Narrow the gap between virtualization's benefits and the management risks.

Cash in on the promise of virtualization

High-performance computing is no longer just for Big Business

Stories of real businesses that Virtualized their IT environments

Learn how companies are changing how they reach out to their most profitable customers.

Data Center ROI with RFID Asset Tracking

Improve Web-Enabled SAP Performance

Gartner on Data Deduplication Cost Savings

Data Protection Options Explained

Webcast - "Into the Wild: Managing Laptops Outside the Office"

Complementary BI: The New Approach to Business Intelligence

5 Steps to Successful IT Consolidation

Effective Security with a Continuous Approach to ISO 27001 Compliance

Optimizing Infrastructure Control

Configuration Assessment: Choosing the Right Solution

Boost your top- and bottom- lines.

Unified Communications & Collaboration: Game-Changing Business Results

Best Intel Info for IT Pros/Intel Premier IT Professional Program: Stay up to date with roadmaps, technologies & best practices

Make Hidden Trends, Inter-Relationships and Influences Visible.

Improve delivery of product information to customers.

Prudential Financial Protects its Brand with Symantec

 
 
RESOURCE CENTER