Virtualization Advisor

Expert analysis and advice on server virtualization technologies, deployments and management.

RSS
All Posts | RSS

Our blogger: Bernard Golden is CEO of consulting firm HyperStratus, which specializes in virtualization, cloud computing and related issues. He is also the author of "Virtualization for Dummies," the best-selling book on virtualization to date.

Mon, August 25, 2008

Antivirus Policies Remain Contradictory for VMware ESX and ESXi

By Edward L. Haletky

Keywords: VMware ESX, ESXi, antiivrus, virtualizatino security policies

Have you read your security policy today? Does it take virtualization into account?

In a previous blog I mentioned that the Defense Information Security Agency (DISA)'s Security Technical Implementation Guide (STIG) had an interesting reason for not running antivirus on the Service Console of ESX. The reason was that the Unix-based antivirus tool recommended in the STIG won't install properly on ESX. There are performance issues and the potential for false positives as well.

Many security policies require that some form of antivirus be run on any system attached to the network unless that system happens to be an appliance.

That presents an interesting picture of its own for VMware infrastructure administrators. VMware ESXi is considered to be an appliance, but VMware ESX is not.

However, I happen to believe that they are both hybrid devices that combine network, storage, and compute resources into one system; sort of a combination of appliance and operating system.

This causes interesting issues with the written security policies that often dictate no multi-homed machines unless it is a switch, router, etc. Well since VMware ESX and ESXi both contain a switch rather than a bridge, do both fall under that rule?

By the same token, it is a compute resource and many security policies dictate that these must contain some form of antivirus, antispyware, and other protection tools.

Because of the differentiation over what is or is not an appliance, ESXi and ESX are treated differently. I think they should be treated the same. (As the management console for VMware ESXi should be secured using many of the same techniques for VMware ESX.)

In either case, running antivirus tools from the management appliances for ESX and ESXi is frowned upon by the virtualization experts for several reasons.

  • antivirus full disk scans will affect performance;
  • VMware ESX/ESXi management appliances provide special use environments where users would not store files, documents, etc.;
  • scanning virtual disk files will produce false positives;
  • the VMware Hypervisor throttles all disk accesses from the management appliances so that reads and writes are very, very slow;
  • there is no current antivirus software for VMware ESXi.

    Security policies will need to be updated to account for VMware ESX or ESXi if this has not already happened.

    Antivirus and multi-homed issues may be just the start of the questions within this all important document, the security policy. When forthcoming VMware VMSafe products are announced by VMware and third parties this will need to be addressed as well. Specifically, an answer to the question "How do you handle the plug-ins for the virtual infrastructure?" must be stated.

    Virtualization expert Edward L. Haletky is the author of "VMWare ESX Server in the Enterprise: Planning and Securing Virtualization Servers," Pearson Education (2008.) He recently left Hewlett-Packard, where he worked in the Virtualization, Linux, and High-Performance Technical Computing teams. Haletky owns AstroArch Consulting, providing virtualization, security, and network consulting and development. Haletky is also a champion and moderator for the VMware discussion forums, providing answers to security and configuration questions.

  • Loading...
    Virtualization Vendor Matrix

    Find out what vendors offer the products you need.

    View the Vendor Matrix »
    Virtualization ABCs

    Get up to speed on virtualization.

    Learn More »
    Virtualization MarketSpace
    MarketSpace White Papers
    Twenty-to-One Consolidation on Intel Architecture: New Tools for Virtualization and Workload Management
    Consolidation isn't easy—especially considering the costs and risks that come with bringing multiple applications and operating systems together on a single mainframe or proprietary platform... Learn more »
    Building the Virtualized Enterprise with VMware Infrastructure
    Many organizations struggle with their legacy IT infrastructures which are often plagued by high costs, slow response times and inconsistent management... Learn more »
    TECHNOLOGY ASSESSMENT: The Impact of Virtualization Software on Operating Environments
    Virtualization is a potential game-changer for modern computing. This IDC Technology Assessment discusses how virtualization technologies impact operating environments, now and in the future... Learn more »
    Reducing Server Total Cost of Ownership with VMware Virtualization Software
    Technology purchases are often quantified simply by hardware and software costs. But there's more to it. This TCO study takes a holistic view—considering soft dollars too, like ongoing maintenance and... Learn more »
     
    SPONSORED LINKS
     

    Learn how to leverage virtualization for a 74% savings in TCO.

    Find out how you can affordably consolidate applications with VMware.

    ESG Research on Server and Storage Virtualization

    Get help navigating the management challenges of virtualization.

    Narrow the gap between virtualization's benefits and the management risks.

    Cash in on the promise of virtualization

    High-performance computing is no longer just for Big Business

    Stories of real businesses that Virtualized their IT environments

    Learn how companies are changing how they reach out to their most profitable customers.

    Data Center ROI with RFID Asset Tracking

    Improve Web-Enabled SAP Performance

    Gartner on Data Deduplication Cost Savings

    Data Protection Options Explained

    Webcast - "Into the Wild: Managing Laptops Outside the Office"

    Complementary BI: The New Approach to Business Intelligence

    5 Steps to Successful IT Consolidation

    Effective Security with a Continuous Approach to ISO 27001 Compliance

    Optimizing Infrastructure Control

    Configuration Assessment: Choosing the Right Solution

    Boost your top- and bottom- lines.

    Unified Communications & Collaboration: Game-Changing Business Results

    Best Intel Info for IT Pros/Intel Premier IT Professional Program: Stay up to date with roadmaps, technologies & best practices

    Make Hidden Trends, Inter-Relationships and Influences Visible.

    Improve delivery of product information to customers.

    Prudential Financial Protects its Brand with Symantec

    Find out why IDC thinks virtualization is changing operating environments.

    Explore the impact virtualization can have on your bottom-line.

    Save with 0% Lease Offer on HP Servers and Storage

    Find out how to manage virtualization's risks and reap the rewards.

    Conquer the realities of managing virtualization

    Expand High-Performance Computing (HPC) Capabilities

    Power the Platform of Choice for Virtualization in the Enterprise

    Virtualization: Simplify. Automate. Lower Costs.

    The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

    How RFID Improves Data Center Efficiency

    Determine the ROI of Web Application Acceleration Managed Services

    Achieve a 50:1 Data Deduplication Ratio

    Remote Infrastructure Management - What Your Peers are Thinking

    Ponemon Study: How Much Does a Data Breach "Cost"?

    Data Protection: Challenges for the Traveling User

    Optimizing Infrastructure Control

    File Integrity Monitoring: Secure Your Virtual and Physical IT Environments

    Effective Security with a Continuous Approach to ISO 27001 Compliance

    Leading university calls on Nokia for mobile unified communications.

    Mobility is Growing: Survey Shows Why CIOs are Concerned

    Learn what it takes to build a holistic digital collaboration platform

    The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

    Customer Insight Yields Sales, Marketing Gains

    7 Requirements of Data Loss Prevention

    Learn About the Features of the Google Universal Search Solution.

     
     
    RESOURCE CENTER