Advertisement
Promo

Server platforms Toolkit

Server Management

Real approaches to virtual security

Tom Espiner ZDNet.co.uk

Published: 09 Jun 2008 15:47 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

...either in the system itself, or in a virtual machine which then acts as a security enforcer for the hypervisor.

Some experts even claim security software embedded in the hypervisor could be more efficient than traditional antivirus installed on separate physical machines. However, there is still the necessity for the hypervisor to be as compact as possible for information assurance purposes, as the bigger the system is, the more code there is to exploit.

It's also possible to embed security in virtual systems by using platform integration mechanisms, which work by scanning systems on start-up to detect changes. When booting up, the systems hardware itself checks for any systems changes, which would detect whether any malicious code had been installed. This isn't used very often, as systems can legitimately change too: for example, if you patch them. However, Mayers argues that platform integration can work for hypervisors as the code doesn't change very often.

"With platform integration, you can tell if you get a hyperjacking attack," says Mayers. If you do suffer such an attack, you can tell when the system reboots. To overcome the issue for systems that are not rebooted very often, Mayers said security should run in a separate virtual machine, with the caution that virtual machines cannot provide physical enforcement.

The problem of how to provide physical as well as virtual enforcement can be partially overcome by keeping networks separate. Experts agree that different types of network, such as LAN, iSCSI and VLAN, should be kept apart.

Virtual local area networks (VLANs) use virtual switches to route data, and these virtual switches are also potentially open to attack, according to analyst Buss. For example, one server with a hypervisor running five virtual operating systems, will communicate over a virtual network interface, and connect to a virtual switch acting as an ethernet port. A firewall or intrusion prevention system between the hypervisor and the virtual switch protect the applications in the virtual environment from being compromised.

Avoid single points of failure
After setting up a virtualised system, a disaster-recovery test is a good way to check that the security implementation hasn't introduced single points of failure into systems, advises Mayers. Hypervisors should be installed in more than one place, so if one part of the system goes down the whole edifice doesn't topple.

Read this

Comment
An open approach to virtualisation management

Nick Carr, product director at Red Hat, discusses the open-source alternatives to the virtualisation- management tools touted by Microsoft and others

Read more +

To test for single points of failure in virtualised systems, Mayers recommends live disaster-recovery tests. "A test will discern if you have any single points of failure. Look at the impact of concentration: how many virtual machines you have on a single physical machine. If that fails, what load does that place on other machines?"

Static security policies — basically pre-defined rules of how to secure a fixed network — might be de rigueur for networks composed of physical devices with fixed software, but they are practically no use when it comes to virtualised systems. "When you have a static policy, you need to think that this machine will communicate with one over there," says Mayers. "If a physical system fails you need to think where a virtual can be moved, and still be secure. If this virtual machine moves, does this break the security policy?"

Beware 'vmsprawl'
And the idea that too much of good thing can be bad for you also holds true for virtualisation. Avoiding 'vmsprawl' — basically deploying new virtual machines unchecked — is a must according to experts. "They'll [virtual machines] proliferate if you're not careful," says Mayers. "You can control vmsprawl proactively, by controlling who produces virtual machines, or you can use discovery to detect virtual machines."

Organisations with tighter security needs often control who can create virtual machines, whereas businesses that need more flexibility monitor their virtual network to discover when virtual machines have been created. However, companies using the latter method have to decide about the risk to their business of rogue virtual machines that have been taken over by malicious controllers.

"What do you do about rogue virtual machines? You need to be able to take those down quickly. IDS [intrusion detection system] relies on being able to see all of the communications in a network — you can still have rogue machines communicating outside the network," says Mayers.

Virtualisation has had a disruptive effect on the whole area of server and network management, and is widely seen as a technology that rewards a brave and bold approach. However, when it comes to securing the systems, experts seem to agree that a measured and step-by-step approach is best and that virtualised systems face as many security issues as their physical forebears. Get the implementation of security for virtualised systems right first time, and you'll save yourself headaches further down the line.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments

More in this Special Report

The server OS: Present and future trends

The server OS: Present and future trends

ZDNet.co.uk research has provided some interesting insights about how server operating systems and management are developing more

Making sense of multicore pricing

Making sense of multicore pricing

Having multiple cores on one processor has its benefits, but simpler software licensing is not one of them more

Living with Microsoft Windows Server 2008

Living with Microsoft Windows Server 2008

Ryan Pothecary, technical architect for hosting company eLinia, discusses his experience as an early adopter of the server OS more

Not Linux? No point, other UNIXes

Not Linux? No point, other UNIXes

Is there anyone seriously suggesting these days that a non-Open Source Linux is worth having? more

What are the top five - even top three - most desired server OS features?

What are the top five - even top three - most desired server OS features?

Of these eleven features, what ranking do you think the real-life IT professionals who took part on our online survey applied to them? more

Trying to map out what the server of the future will look like

Trying to map out what the server of the future will look like

ZDNet UK recently carried out a poll of readers to gauge opinion and experiences around issues to do with the server OS question more

Blog: Microsoft in 'quite good' shocker..

Blog: Microsoft in 'quite good' shocker..

Windows Server 2008 is actually quite good...There's lots of things that have been improved upon and new features that truly, either make our lives easier or make our servers more secure more

CPU roadmap: server processors

CPU roadmap: server processors

How are the roadmaps of the leading server processor vendors shaping up for 2009 and beyond? We pore over Intel, AMD, IBM and Sun's latest plans. more

The realities of server management: Part 1

The realities of server management: Part 1

Based on research from ZDNet.co.uk, IT managers debate the issues surrounding server management and the future of server operating systems more

The realities of server management: Part 2

The realities of server management: Part 2

IT managers and industry analysts debate issues around server management, both on open-source and proprietary platforms more

The realities of server management: Part 3

The realities of server management: Part 3

IT managers with expertise in Linux and Windows discuss how both platforms have their challenges when it comes to server management more

Microsoft finally launches Hyper-V

Microsoft finally launches Hyper-V

Analysts have welcomed the release of the hypervisor, but rival VMware claims Hyper-V has been a long time coming and lacks functionality more

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Microsoft Futures

Windows 7: Mixed reviews from PDC attendees

As developers received their copies of Windows 7 on Tuesday, they offered varied reactions to the Microsoft operating system update More

Microsoft floats clouds on Windows Azure

At the Professional Developers Conference, Microsoft announced the Azure Services Platform, the company's cloud-computing platform More

Ozzie: Success of Azure comes down to trust

In an interview, Ray Ozzie says businesses will be taking a risk by placing core operations in Microsoft's datacentre, but that the software giant has more to lose if things go bad More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters