Unfriendly software security risk for desktop virtualization

 

Summary

Security tools not "aware" of virtual desktop infrastructure can cause resource challenges leading companies to risky move of abandoning security altogether, warns vendor.

Events

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

End-point security software are not built with desktop virtualization in mind and this is proving to be one of the biggest management challenges in virtual desktop infrastructure (VDI) environments today.

According to Richard Sheng, Trend Micro's Asia-Pacific regional director for business development and product marketing, because existing endpoint security tools are unable to recognize the presence of virtual machines, they contend for resources at the CPU, storage and network levels.

On physical machines, such utilization of resources would not be significant but in desktop virtualization, where multiple desktops are co-located on one physical server, the base load on that machine is considerably more strenuous.

Sheng explained in an e-mail: "Take the so-called '9 a.m. problem' when workers come to their desk in the morning and start up their virtual image. Immediately the images would reach out to download the latest security updates, like filters and scan-engine updates. This leads to serious contention on the CPU and the storage side."

Similarly, when a scheduled malware scan runs on a VDI system, it overloads the CPU and storage capacity, causing all task sessions to slow down. Sometimes, users are unable to even login and virtual sessions get dropped, he noted, adding that the entire VDI host may even come to a complete halt.

As a result, Sheng warned that customers may resort to removing security completely from their VDI installations, exposing their desktops to significant risk.

Trend Micro last month announced the OfficeScan 10.5, which the company touts can decrease scan-time as well as memory consumption and CPU utilization by up to 80 percent in a VDI environment. "Customers no longer have to choose between security and VDI returns on investment," said Sheng.

Security inherent, but still a must in desktop virtualization
Martin Duursma, vice president of Citrix Labs and chair of the CTO Office, noted that security is one of the inherent capabilities of a VDI offering as data and applications are under the control of the data center, not the endpoint.

"As soon as you can start to centralize information, it has to be a more secure solution than when you move files, presentations, content down to a laptop," Duursma said in an interview at the Citrix iForum 2010 held in Singapore earlier this month.

"Today when organizations have PCs or laptops, they lose control of their corporate information--people are downloading corporate spreadsheets and files onto machines," he noted. "There's a spread of information and the IT [department] has really little knowledge of where it's all going. When you use a VDI, that spread doesn't occur."

Neville Burdan, Datacraft Asia's general manager for Microsoft solutions, concurred. However, he pointed out that the enhanced security does not remove the "need for good security practices on the desktop", such as putting in place virus protection and encryption technologies.

"Many people think that because [management of] the desktop is now placed in the data center, they do not need to do this. However, this is not true," Burdan said.

"Secure your desktop just as you would with your laptop, then you will have new tools and benefits of backing data and managing the image in the data center but remember to secure those desktops," he said.

Trend Micro's Sheng also advised companies to, from a risk management perspective, treat a VDI desktop like any other desktop. "We acknowledge that VDI desktops are easier to revert to a clean state if infected, but the risk of getting infected is the same as with a physical desktop.

"[This means] the risk of spreading malware and exposing corporate or sensitive personal information is the same," he said.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Malaysia organizations don't realize severity of cyberattacks http://t.co/PUCv68Rd

News: Radio Costa Rica by EnjoyIT 1.0: Radio Costa Rica allows you to listen to a great var... http://t.co/BLzVT5As http://t.co/1Dhcy6ki

The key for mobile operators is identifying the applications that are popular with subscribers on their network. They can then work partn...

1 hour ago by camcullen on Experience trumps content in apps monetization

Experience trumps content in apps monetization | ZDNet http://t.co/gBXcjbGd

Experience trumps content in apps monetization - ZDNet Asia News: "What we are doing currently is not to monetiz... http://t.co/S2EZtd8m

Malaysia organizations don't realize severity of cyberattacks: "Minister Maximus Johnity Ongkili said at the Sec... http://t.co/bgVlOBvx

#security Malaysia organizations don't realize severity of cyberattacks: "Minister Maximus Johnity Ongkili said ... http://t.co/hkFb4zrI

Malaysia organizations don't realize severity of cyberattacks http://t.co/EEEmRM3j via @zdnetasia

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia News http://t.co/YpNMYgb5

Malaysia organizations don't realize severity of cyberattacks http://t.co/FFems54Q

China solar cell makers seek Taiwan partnerships http://t.co/p5Hh7kJD

Big data acquisitions pave way to fast, effective innovation http://t.co/hdiEfBsz via @zdnetasia

Integration, focused investments to propel Windows Phone: By Kevin Kwang , ZDNet Asia on May 23, 2012 (2 hours a... http://t.co/E7tsZbHJ

Integration, focused investments to propel Windows Phone http://t.co/u9TqjQ8C

ZDNet Asia IT Salary Benchmark 2012 http://t.co/rVwYlV7H

AsiaClassifiedToday. Integration, focused investments to propel Windows Phone - ZDNet Asia: S... http://t.co/47tdjZyG #asia #google #biz

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

3 days ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

5 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

5 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

5 days ago by wykoong on Drop the egos, copy ideas, then innovate