home news blogs forums events research newsletter whitepapers careers


UBM Network Computing
TechWeb
Visit our SOA/Web Services Immersion Center

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Network Computing Blog
Lead Analyst:
Jordan Wiens
Jordan Wiens


More analysis, strategies and news at our
Data Privacy
Immersion Center


Subcribe to This Blog's
RSS Feed
Lead Analyst:
Art Wittmann
Art Wittmann


More analysis, strategies and news at our
Data Center
Immersion Center


Subcribe to This Blog's
RSS Feed
Lead Virtualization Analyst:
Joe Hernick
Joe Hernick


:: More analysis, strategies and news at our
Virtualization Immersion Center


:: Subcribe to This Blog's
RSS Feed
Lead NAC Analyst:
Mike Fratto
Mike Fratto


:: More analysis, strategies and news at our
NAC Immersion Center


:: Subcribe to This Blog's
RSS Feed
SPECIAL EVENT BLOGS:
BrainShare 2008

IMMERSION CENTER BLOGS:
Network Access Control
Virtualization
Application Performance Optimization
Data Center
Data Privacy
802.11n
SOA/Web Services

MORE TOPCS:
Security
Wireless
Application Infrastructure
Collaboration
Network and Systems Management
Network Infrastructure
Storage and Servers
Enterprise Applications
Business Strategy
Personal Technology
Podcasts
NWC Inc
NWC Labs
Techno-Oddities

MORE GREAT BLOGS
Ars Technica
bMighty
Boing Boing
Geek.com
InformationWeek
IT Toolbox
TechCrunch



NAC Immersion Center Blog
Virtualization Immersion Center Blog
Data Center Immersion Center Blog
Data Privacy Immersion Center Blog

April 09, 2008
Virtualization Security: A Solution Looking For A Problem?
By Mike Fratto

One of the themes coming from RSA and from vendors in the last few months is the notion that virtual servers, whether running on a hypervisor or not, are somehow more at risk that physical servers. I don't buy it entirely because servers and applications that are virtualized tend to be in tightly controlled data centers. If your data center is secure, so are your servers. Why treat virtualized servers special?

The type of security, by the way, isn't ensuring separation of data and resources within the hypervisor, rather the security problem is that traditional network security functions like firewall, IDS/IPS, and content filtering are difficult to achieve within the virtual switch itself -- interserver server communications that never cross the wire. After expressing my skepticism to a few vendors at the show, the product pitches carried a hint of desperation or aggravation (I couldn't tell which), trying to convince my why security in the hypervisor is important.

The common statement and leading questions are:

  • Well, having security near the servers is important, right? Yes, but that’s a leading question. What am I going to say, no, security near the servers is a bad idea? Thing is, a data center is unlike the rest of the network. It's a controlled environment where you should know what is happening, you don't have random users connecting to the wire, and server-to-server communications are contained within the data center. Communications passing beyond the data center perimeter can be controlled at the choke point.

  • Which leads to the statement that the reason why there is often little internal security in the data center is the cost to deploy targeted security inside the data center and the relatively high-capacity requirements, which is often multi-GB to 10 GB or more. The bang for the buck is low. However, putting security functions in the hypervisor is less expensive than hardware. Not free, just less expensive, so the cost of license fees has to be accounted for and, of course, the performance hit within the virtualized environment.

  • Virtulalization features like VMWares VMotion that allows a running VM to be moved seamlessly between hypervisors creates a far more dynamic environment than with standalone physical computers. Granted, the environment can be more dynamic, but if a company loses control of its virtualized servers, it has big problems anyway.

  • Finally, initiatives using virtualized servers to create like virtualized desktops for users is an interesting use of virtualization, but do you really want to intermingle your users with your data center? That's like plugging your access switches directly into the data center. Virtual desktops should be partitioned off from the data center and treated like any other desktop.

All of this is great in theory and I could very well be missing the threats to virtualized servers, but I really don't see any difference in risk or threats between a server or application running on bare iron versus running on a hypervisor. If your data center has good controls and is following good management processes already, those processes will apply to all servers.

Granted, there are some considerations specific to virtualization, like preventing resource starvation, ensuring the hypervisor is properly hardened, ensuring that there are effective controls to make sure that VM resources such as memory, disk, CPU instructions, etc., within the same hypervisor are partitioned.

Like anything regarding security, you need to first determine what the threat vectors are to a resource, the who and how, first, and then develop controls to mitigate the successful exploitation of the threat. Once the controls are identified, you have to determine where to employ them in a virtualized environment. Interserver communication in an n-tier application may be controlled within the network if you can guarantee that various servers will always communicate through the physical network. That is an architectural process issue. However, if interserver communications occur between servers on the same hypervisor, then a hypervisor-based integrated product may be necessary and there are several vendors like Reflex Security or Montego Networks that have products to suit and I am sure there are others. Of course, there also are host-based solutions that can be used on servers real or virtualized. Just don't get caught up in the virtualization hype. A computer is a computer and good management practices are your only patch to success.

-- Posted at 01:55 PM in Data Center Immersion Center | Data Privacy Immersion Center | NAC Immersion Center | Virtualization Immersion Center





This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.








Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Purchase Today: $299
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Media Kit  |   Briefing Centers
Other Techweb Sites:   InformationWeek Reports  |  Intelligent Enterprise  |  Light Reading  |  InformationWeek
Techweb  |  Dark Reading  |  Network Computing Germany  |   Byte & Switch  |  bMighty  |  Small Biz Resource  |  InformationWeek Analytics
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights