Reasons to care about Viacom v. Google - Zd Net Asia.com: Last Thursday's 200-page dump of cour... http://bit.ly/crqRzF #SME #UMG #WMG #EMI
1 hour 50 minutes ago by metaphysicalist on topsyZDNet is available in the following editions:
Server virtualization makes business sense, but too many companies are deploying the technology without considering the security implications.
Server virtualization is a no-brainer--it's quick to deploy and easy to justify in terms of cost-savings--but too many companies are deploying the technology without considering the security implications.
Server virtualization has been the hottest trend in enterprise IT for some time and according to IBRS analyst Kevin McIsaac, it's likely to remain that way for the next two to three years.
IBRS estimates that one in three large Australian organizations has deployed server virtualization within their data center, and nearly every medium to large enterprise has at least looked at a pilot for the technology.
But as the push to consolidate physical servers intensifies, questions are being raised as to whether new virtual servers are being deployed with adequate security measures in place.
Hypervisor hackers
Virtualization software uses programs called hypervisors, which allow multiple operating systems to run on the same hardware.
Hypervisors have to date been considered fairly secure programs, in that they tend to carry a smaller footprint than an operating system and thus carry a lower potential for security holes.
"I don't know if anyone has ever seen a working prototype or found a virus in the wild that attacks the hypervisor," McIsaac said. "There is a lot less code in a hypervisor, only a fraction of what's in an operating system, and unlike an operating system, you won't find a hypervisor surfing the Internet and downloading code."
That said, the hypervisor is an obvious target for hackers. If compromised, it could potentially provide access to a range of services within a virtualized machine, rather than to a single service in a standalone box.
Security analysts and white hat hackers have done their best to crack the hypervisors of the leading brands, to little success. Malware researcher Joanne Rutkowska talked up an attack method called "Blue Pill" at a recent security conference in August, but this has since been debunked by several industry figures as detectable and addressable.
Most of the reported hacks of virtualization software, reports VMWare systems engineer Andrew Kemp, are clutching at straws. One exploit, he said, which has since been patched, required the attacker to physically be inside the server room, logged on at a specific time and using a specific version of VMWare's ESXs software.
"If you have someone in your data center, you've got plenty of other problems to worry about," he said.
Nonetheless, there is no shortage of hackers having a crack at the technology.
Gartner security analyst Andrew Walls says it's a sure bet that there are people in the hacker community "trying to develop exploits that target the hypervisor."
A process problem
It's for this reason that Gartner vice president Neil MacDonald released a controversial statement in April warning organizations not to rush into deploying server virtualization without studying its potential for security risks.
MacDonald argued that hypervisors represented a "new layer of privileged software" that needs protection, and said that virtualization vendors and their third party tool developer partners were releasing "immature and incomplete security and management tools."
This sentiment didn't go down to well in the virtualization vendor community, who decried the statement as being alarmist.
Nonetheless, Gartner's Walls claims he was trying to make a very important point about virtualization and server consolidation projects.
Virtual servers, Walls explains, are quick, easy and cheap to deploy, and as such can be deployed with the kind of abandon that has little regard for security.
It's a risk that is coming to be known as "virtual machine sprawl".
Without the right user rights and privileges controls in place, virtualization tools allow knowledge workers to deploy a new server instance or virtual machine without the consent or control of IT security staff.
"The main risk Gartner sees is to do with the segmentation of duty," Walls said. "It's about organizational structure, not technology."
In the non-virtualized world, Walls explains, it's always been fairly clear as to what the protocol for IT security is.
In larger organizations, security concerns have often warranted dedicated staff. So while the IT admin team is responsible for the day-to-day running of new servers, the security team try to monitor and maintain control.
"You need to be careful that the use of virtual servers doesn't erode any responsibility," Walls said. "The big advantage to virtualization is the speed of deployment. You can deploy ten new servers in an hour. But when you have a much faster deployment model, you can rapidly increase the number of targets for attack."
If the rush to deploy new security is left to IT admin, Walls said, there is a potential for the quality of security processes to be compromised.
"IT seeks to optimise performance, to deploy new instances, at reduced cost," he said. "They are strongly motivated to meet the needs of the business, which is always pushing to offer new services and thus new server instances. Security sometimes gets left out."
"Each time a new server is implemented or a new server instance is deployed, you need to ensure that the same governance controls and change controls are applied to this virtual environment as a new server," he said.
Choose carefully
Walls said there is no single virtualization vendor he would favor over another in terms of security.
That said, its safe to say that the less code a hypervisor contains, and the less access available to that code, the more secure the solution.
"There are a lot of skinny hypervisors, and a lot of fat ones," Walls said. "Generally the more functionality it has, the more prone it will be to exploits."
The VMWare hypervisor's footprint is among the thinnest, with the solutions available from Microsoft and the open source movement being a little fatter, he said.
VMWare's Kemp argues that the security vulnerability of one solution can come down to how the vendor manages drivers within the hypervisor.
VMWare, he said, has a "direct hardware model", which sees the vendor write its own binary access to the specific hardware devices the software is compatible with. That, in affect, is why VMWare's hypervisor will only work with a select amount of hardware.
Some of the vendor's competitors, he said, have implemented a "master domain model" in which hardware drivers are written by third parties and stored in a container mechanism.
"We investigated that model thoroughly as far back as 1988--but the security implications drew us away," Kemp said. "The risk of exposure is increased when more people are writing the code."
Security benefits?
For any potential risks that virtualization poses, it can equally be argued that a correctly implemented solution can actually harden an organization's security.
In the network, virtual servers can be deployed as firewalls or monitoring tools--additional defenses against attack.
Using virtualization, sensitive applications can also be consolidated together on hardware that is better protected than the rest of the server farm.
On the desktop, users can use virtualization to conduct their routine Web surfing on a separate partition to the one they use for making sensitive financial transactions, protecting themselves from malware, fraud and identity theft.
That said, one needs to remember that like any software, one can never assume that virtualization tools are beyond attack.
"I am perfectly confident that somebody will write an exploit for the hypervisor," Walls says. If it's any guide, he said "we still haven't built the perfect operating system yet!"
Reasons to care about Viacom v. Google - Zd Net Asia.com: Last Thursday's 200-page dump of cour... http://bit.ly/crqRzF #SME #UMG #WMG #EMI
1 hour 50 minutes ago by metaphysicalist on topsy@BarackObama People voted you in for change. Why are you not listening on ACTA http://tinyurl.com/y8u56g9 #hcr HCR
3 hours 1 minute ago by studio1411 on topsyMB Kabbalah IChing - Free Software Downloads - ZDNet Asia: MB Kabbalah IChing is a zodiac sign based software that... http://bit.ly/czUQRr
3 hours 54 minutes ago by fighting_jew on topsyFound this great little deal calculator http://www.zdnetasia.com/downloa...
11 hours 15 minutes ago by winstoncranford on topsyRead my blog post on getting the most from your Nexus One: http://www.zdnetasia.com/blogs/m...
17 hours 32 minutes ago by mistertechblog on twitterRT @3wconsulting: Whitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oY9f
1 day 46 minutes ago by LeesaAT3W on twitterWhitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oYbA
1 day 47 minutes ago by itemployment on twitterWhitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oYbz
1 day 47 minutes ago by brucemills on twitterZdnetasia.com Estimated Worth $178,365 USD. Daily Ad Revenue:$244 USD, Daily Views:81,445 Pages... - http://www.haplog.com/www.zdneta...
1 day 30 minutes ago by Haplog on twitterThe receivers don't transmit back to the satellite. Unless there is a phone line attached to the receiver, they don't have any wa...
2 days 13 minutes ago by bessellbrowne on Apple to join the geolocation craze?whatever little understanding I have we 'll only progress toward end of the world if we use HPCs to lenthen life of human being. Huma...
2 days 19 minutes ago by abhi32002@gmail.com on High computing promises elixir of lifeThanks for the knowledgeable article on SDDs. Allas...when all this reasearch will happen in Indian Universities. Hope the new bill on Fo...
2 days 32 minutes ago by abhi32002@gmail.com on APAC HPC users eye solid-state drivesIt was a good article. This brings a good opportunity for Indian IT firms to come up with new solutions in this field. HPC can become a b...
2 days 51 minutes ago by abhi32002@gmail.com on High computing most-wanted job in AsiaCOL KR DHARMADHIKARY(RETD) its very late to reply the link, but if it is still alive and looking for opportunity, i would like to know th...
2 days 48 minutes ago by deb021280 on Education takes off in rural India, helped by PCsHigh performance computing (HPC) most-wanted job in Asia http://bit.ly/9vFC3i (via @zdnetasia) #singapore
2 days 5 minutes ago by mySingapore on twitterRT @zdnetasia: EMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. (cont) http://tl.gd/i5jjd
2 days 53 minutes ago by mistymaitimoe on twitterEMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. http://bit.ly/9etOZW
2 days 57 minutes ago by zdnetasia on twitterAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08 via @zdnetasia
2 days 13 minutes ago by asiapacsolution on twitterAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08
2 days 28 minutes ago by zdnetasia on twitter"YOG should have social media rules, too - Internet - News" http://bit.ly/dn6vjD
2 days 35 minutes ago by socialsentiment on topsy[TECH] URL Shorteners slow Web redirection. - http://bit.ly/bySnWK @zdnetasia
3 days 11 minutes ago by danielcktan on twitterURL shorteners are great but they can slow web redirection & you pray it would never go down http://bit.ly/bySnWK via @zdnetasia
3 days 39 minutes ago by angahsin on twitterURL shorteners slow Web redirection. http://bit.ly/bySnWK
3 days 8 minutes ago by zdnetasia on twitterChinese agencies cry foul over Google. http://bit.ly/by6rwV
3 days 14 minutes ago by zdnetasia on twitterall of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...
3 days 32 minutes ago by melvinchia on Web filters mean bad news for businessit is not to good for china.
Proactol
Very good explanation of JMX
5 days 22 minutes ago by Babith B on Managing applications with JMXThe reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.
5 days 25 minutes ago by lonemavericks on diggsAnother ZTE story....
5 days 27 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G licenseWe at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.
5 days 460858 seconds ago by sarah Jane on Companies' outsourcing spend to increaseI agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...
5 days 31 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV insteadhermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...
5 days 9 minutes ago by ... on Facebook user charged in MalaysiaPassword manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...
5 days 9 minutes ago by ohanae on What defaults should random password generators use?I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.
5 days 43 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stickThanks for the article. I think the debug command has an "\" after "C:" it should say w32tm /debug /enable /file:C:\l...
5 days 44 minutes ago by Roger Biefer on Manage time accuracy with W32TmThe Desktop Virtualization Revolution is here!
Find our more with Citrix Simplicity is Power
2010 IT Salary & Skills Report
Find out the salary range of IT professionals. Join activeTechPros for free access to the report.
The Internet Show 2010, 21-22 Apr 2010, Singapore
FREE admission for visitors who pre-register online. Register Today!