Business Technology Summit 2010 on SOA and Cloud Computing
Member Login
Password

 

Security in a Virtualised Environment: The New Battleground
Virtualisation has established itself as the next significant dimensional change in enterprise computing. The cost benefit it offers by consolidating underutilised computing resources makes it a critical initiative for IT directors who are instructed to ‘do more with less’. Estimates are that the server virtualisation software market will be worth USD $6.2 billion by the year 2013 and that over 50% of all servers will be virtualised by 2012.

With the rising popularity of virtualisation, heated debates regarding security and compliance have surfaced. The key participants in these debates are, not surprisingly, virtualisation vendors and security providers. Virtualisation vendors claim that isolation functions into their own dedicated environments increases security while security providers counter argue that virtualisation introduces new points of attack and increases vulnerability through recognised virtualisation issues like virtual machine sprawl. It is not possible to agree entirely with either side as they are both true at some levels. As with any new technology, in order to achieve a secure implementation, existing practices and policies need to be augmented with a clear understanding of how virtualisation works.

Your Virtual Machines Aren’t So Invisible After All

On the face of it, VMs appear to be hidden on a virtual network behind or inside physical hardware though Network Address Translation (NAT). This instigates the belief they do not need the same security measures as a physical machine simply because they are invisible to the outside world. However, it needs to be understood that every VM has its own IP address and has a communication port to interact with the outside world leaving it open to the same vulnerabilities and threats as a separate physical machine.

Plain virtualisation isn’t a security measure by itself. This rule holds well for another similar credence that VMs are somehow hidden behind the host operating system or the hypervisor. Even if the VMs are 'hidden' behind Network Address Translation (NAT), and not directly reachable, their basic operation is to offer a service such as e-mail, Web or a database, which is forwarded to them through that protective layer. Those services can still be attacked through the hypervisor.

Application attacks, particularly to Web applications, are an increasingly common attack vector. Simply put, VMs must comply with and maintain the same level of security as the physical system on the network and a virtualised application is as vulnerable to exploit as a non virtual one.

VMSprawl Gives your Security Staff a New Issue to Deal With

Due to the constant stream of communication between virtual machines in a virtualised environment, monitoring and analyzing data traffic becomes an exponentially tough job for people responsible of security. The complexity of this issue magnifies as the number of virtual machines increase.

It doesn’t help when an IT manager decides to launch various individual VMs for each trivial application. This is a classic VMsprawl condition and has the potential to introduce even higher levels of risk to the organisation and further degrade network performance.

Deploying virtualisation requires additional security monitoring of the administration activities, the virtualisation management interface, and access to the virtual machine logs, messages and events. Much of this data will also need to be retained for security investigations and compliance reporting. Effective monitoring and reporting across a virtual environment can be tricky as virtual resources and their associated security and compliance data migrate between physical systems and potentially disappear all together.

Security monitoring and reporting can be achieved by first performing an inventory of the security and compliance data your physical and virtual resources generate, including the location (memory, file system, network port) and the best way to access that data. Often times, accessing the logs and messages from a virtualised environment can be tricky, since most virtualisation vendors haven’t designed very robust, scalable APIs or data forwarding mechanisms.
Capturing data in near real time is important given the migration and volatility of virtual resources and data. Once the data sources and collection mechanisms are identified, you will need to deploy a security event management and reporting solution to correlate the different types of events and technologies in your virtual stack (applications, operating system, network, storage, access control).

It is recommended not to deploy security monitoring and reporting solutions as part of the virtualised environment, sine administrators have the ability to remove traces of their own activity. Once your data is consolidated, the logs, events and message can be correlated to provide actionable alerts, enable comprehensive security investigations, speed troubleshooting of complex problems and archived to meet compliance retention and reporting requirements

Restricting Hypervisor Access

The introduction of a hypervisor requires additional management software. This raises security concerns because the management software grants administrative access to multiple VMs.

Imagine an instance where 50 hosts live on a single server and you understand how a hypervisor attack could have extremely serious ramifications. To address this issue, establish role based access controls for individual VMs through the physical access controls that have been established before virtualisation.

Additionally, establish network based firewall controls to limit network access to administrative interfaces. Severely restrict the number of administrators that have console/root level access to the host operating system. This access, as well as all administrative activities, must be logged to a centralised log management server similar to the security monitoring measures listed above. In addition to access controls, utilise encryption and monitoring software to avoid sniffing of administrator credentials and to monitor abuse of administrator privileges.

Virtualisation has changed the way we think about computing infrastructure. Now virtualisation security has to be rethought as well. An information-centric approach to persistently protecting the data itself is the only way to really benefit from virtualisation and keep data truly secure.
Related Articles
3PAR Unveils Utility Storage in India 3PAR, a global provider of utility...
Security in a Virtualised Environment: The New Battleground Virtualisation has established itself as...
Related Podcasts & Videos
Business Transformation vs. SOA Transformation - Can I do Both? Corporations are transforming their business models in an attempt to increase revenue, operational efficiency and global competition by designing innovative business models and processes to be disruptive in their market space. In this keynote, recorded at Saltmarch Media's Business Technology Summit 2008, the Vice President of IBM's Global Solutions and Assets division says business leaders are looking for IT to provide and support the disruptive business models. However, the majority of IT's budget and resources are spent in maintenance leaving little time and resources for IT to be innovative and meet the business demands. In addition, many IT Corporations have adopted SOA in adhoc fashion and achieved some maturity in the technology. The key to aligning the IT objectives with the business objectives is a structured approach. Come hear about new ways to develop the required capabilities and prioritize the initiatives to create a Business and SOA transformation roadmap.
State of the Union - SOA Standards The author of the seminal book "Great Global Grid: Emerging Technology Strategies" discusses the current status of SOA-related standards and their applicability in this talk recorded at Saltmarch Media's Business Technology Summit 2008. This has been an active area over the last few years with multiple standards being developed and supported by different organizations. However there are still concerns about the complexity and maturity of SOA standards. The content will be based on Bob's recommendations for government agencies in the US and Asia. It will also include information from an "Emerging Standards for SOA" Session that Bob organized bringing together leading standards groups.
Virtualization 360 Increase your virtualization IQ: learn about Microsoft's virtualization roadmap, understand the technologies and get ready for the Virtualization from Ravi Sankar. This session, recorded at Saltmarch Media's Business Technology Summit 2008, will provide you with an overview of Microsoft's comprehensive virtualization strategy and product offerings, including server virtualization and management (Hyper-V and System Center Virtual Machine Manager 2008), Microsoft Application Virtualization, presentation virtualization (Terminal Services) and desktop virtualization (Virtual PC 2007, App-V).
Software + Services: Fundamental Shifts in Platform Computing We are at the cusp of a big industry change. The way software is delivered and monetized is undergoing a fundamental shift. The multiple models for monetization are fundamentally shifting the software industry and business models. Traditionally software companies have made monies only in Licensing and now there are three additional models to monetize. In this talk recorded at Saltmarch Media's Business Technology Summit 2008, Srikanth Karnakota says software licensing is going to continue to exist and grow. Online advertising will grow. Online transactions and subscriptions will grow. But perhaps most importantly for a number of our partners, the amount of value that will be delivered by humans providing customization services, application development services, management services, hosting services, will also continue to grow, and so we see a big opportunity for our partners as we make this transformation to Windows and Windows Live and the new software plus service user interface and computing model.
Doing More With Less In the Downturn - Interview with Embarcadero's Philip Rathle Having affordable access to the right tools at the right time has never been more important, especially with today’s intense scrutiny on budgets and expectations to do more with less. Centered on the theme of recession storming, over fifty top level IT decision makers joined Saltmarch Media and Embarcadero Technologies with the objective of demystifying the changing IT environment and its impact on global business. Watch this full interview with Philip Rathle, Director of Product Management, Embarcadero All Access.
Manish Gupta, CIO, Healthcare Global, on Storming the Recession At Saltmarch Intelligence's All Access CIO Meet held in Bangalore, India, in collaboration with Embracadero, Manish Gupta, CIO of Healthcare Global Inc, shared his views on the strategic decisions that are critical for the survival of enterprises. Every organization, across verticals, is being forced to rethink different measures to survive and overcome the heat of this recession. “In this economic climate, making the right decision at the right time has never been more important for corporate success - or even survival,” said Manish. Watch the full interview with Manish.
Most Popular
Most Read

Softlink Logistic Systems, an Indian logistics software provider, today revealed the survey results on – ‘Adoption of Technology in Indian Logistics Sector-2009’, conducted amongst 700 Indian logistics players operating as Customs Clearing, Freight Forwarding, NVOCCs and 3PL players. The survey revealed that larger logistic players are opening up for technology investments in the year 2010. It highlights that the number of larger players, making technology investments up to Rs. 10 mn have been doubled to 14 percent in 2010 compared to last year.

3PAR, a global provider of utility storage, has launched its first sales and customer service office in India and has named Arvind Khurana as country manager. This move into India is intended to position 3PAR to meet growing demand for technologies to support cloud computing, the virtual datacenter,green IT initiatives, and enhanced infrastructure agility in an economy that has been expanding in the midst of a worldwide recession.

Virtualisation has established itself as the next significant dimensional change in enterprise computing. The cost benefit it offers by consolidating underutilised computing resources makes it a critical initiative for IT directors who are instructed to ‘do more with less’. Estimates are that the server virtualisation software market will be worth USD $6.2 billion by the year 2013 and that over 50% of all servers will be virtualised by 2012. With the rising popularity of virtualisation, heated debates regarding security and compliance have surfaced. As with any new technology, in order to achieve a secure implementation, existing practices and policies need to be augmented with a clear understanding of how virtualisation works.

Softlink Logistic Systems, an Indian logistics software provider, today revealed the survey results on – ‘Adoption of Technology in Indian Logistics Sector-2009’, conducted amongst 700 Indian logistics players operating as Customs Clearing, Freight Forwarding, NVOCCs and 3PL players. The survey revealed that larger logistic players are opening up for technology investments in the year 2010. It highlights that the number of larger players, making technology investments up to Rs. 10 mn have been doubled to 14 percent in 2010 compared to last year.

India-based companies have emerged as the most trusted ones, with the technology sector being ranked the highest in terms of transparency and credibility, according to the recently released report from Edelman Trust Barometer. India-headquartered companies are trusted by a majority of people in the country. While US' trust in technology is 78 percent and China is 83 percent, in India it is 88 percent. Technology is the most trusted sector in India at 88%, followed by banks, automotive (79%), pharmaceuticals (75%), healthcare (73%), entertainment (70%) and media at a relatively low 58%.

Citrix is lending a helping hand to companies looking at lowering their infrastructure costs. Its newly released XenDesktop 4 server with FlexCast technology can deliver up to 125 virtual-based desktops, 500 hosted shared desktops and 5000 local streamed desktops from a single physical server. The company says the new desktop virtualisation solution was made possible with Intel's Xeon processor 5500 technology. With XenDesktop 4, desktop virtualisation can now possibly be implemented with 20 percent lower infrastructure costs.

Advertisement

More Videos

Business Transformation vs. SOA Transformation - Can I do Both? Corporations are transforming their business models in an attempt to increase revenue, operational efficiency and global competition by designing innovative business models and processes to be disruptive in their market space. In this keynote, recorded at Saltmarch Media's Business Technology Summit 2008, the Vice President of IBM's Global Solutions and Assets division says business leaders are looking for IT to provide and support the disruptive business models. However, the majority of IT's budget and resources are spent in maintenance leaving little time and resources for IT to be innovative and meet the business demands. In addition, many IT Corporations have adopted SOA in adhoc fashion and achieved some maturity in the technology. The key to aligning the IT objectives with the business objectives is a structured approach. Come hear about new ways to develop the required capabilities and prioritize the initiatives to create a Business and SOA transformation roadmap.

More...
Off the Press

Indians Most Trust its IT Sector and India Headquartered Companies India-based companies have emerged as the most trusted ones, with the technology sector being ranked the highest in terms of transparency and credibility, according to the recently released report...

Intel-powered Citrix XenDesktop Claims to Run 5000 Desktops from one Virtualisation Server Citrix is lending a helping hand to companies looking at lowering their infrastructure costs. Its newly released XenDesktop 4 server with FlexCast technology can deliver up to 125 virtual-based...

BMC Software Acquires Phurnace Software BMC Software has acquired Phurnace Software, a developer of Java-based automation software aimed at significantly reducing the cost, complexity and risk to deploy and configure Java-based...

More...
Whitepapers

Bringing the Edge to the Data Center: a Data Protection strategy for SMEs with Remote Offices Small and midsize businesses with remote offices need data protection strategies that are closely aligned with their business priorities, IT infrastructure, and regulatory requirements for data...

Desktop Delivery: Making Desktop Virtualization Work This whitepaper discusses Desktop Virtualization and the impact on desktop management challenges, and considers the challenges for desktop management in a pre-Desktop Virtualization world, how...

Server Energy Efficiency Implications on Large Scale Datacenters Trends in servers are pushing cloud computing providers and in-house data center operators to restructure their organizations, eliminate misplaced incentives, increase capital utilization, and...

More...