To advertise, contact
Matthew Armstrong
+971 4 2108520
matthew.armstrong
@itp.com
بالعربية
Where am I? Home /


BREAKING NEWS :

Virtual Environments Need Protection Too

By Karel Rode on Thursday, May 15, 2008


In my day-to-day travel to and from the office, I often expect virtual reality to step in and transform my boring and often outright dangerous trip into something more surreal and interesting.

Sadly, this will not be the case for another few years, but the networking teams and even some of the 'old timers' with big iron mainframes are revitalising computing nonetheless.

Taking one 'honking big box' and running many servers within a virtual environment have been available to us for some time now with VMware, MS Virtual PC, Parallels (for Mac) and some lesser know Linux options maturing. The more serious players have taken to running virtual Linux sessions of the OS390 with spectacular results.

Sadly, Ed Skoudis and Tom Liston from Intelguardians have found ways to crash systems with virtual machines on them and have even been able to run their own code on the host OS. Though done in a very controlled manner and with little exposure, it does beg the question of when will we see such exploits in the wild?

So then the sexy bit will be escaping the VM. Our focus for now though should be on protecting the virtual environments in a same way as we do our real systems. Experience tells me that some sys-admins do not do as good a job of treating the virtual machines with the same level of care as they do to the real hosts. Therefore, patch levels and administrative privileges must not be treated differently just because we run VMs.
Story continues below
advertisement



Moreover, the virtual machine technology of choice may require one or more updates just like the system OS, and should therefore be treated just like any other business application when it comes to risk mitigation and management.

Going green

When starting to run multiple instances of virtual machines, companies may introduce a hypervisor or virtual machine monitor. These systems are also vulnerable just like any other machine and OS, and as it will have privileged access to all or most VMs, they need to take special care of it.

There are many benefits to virtualisation though. The more obvious are reduction of hardware costs or increased utilisation of current hardware. The green IT discussion will also come up as we now reduce power consumption as well as cooling requirements and an overall reduction in floor space.

Virtual technologies and management solutions also now provide for failover and high availability with capacity management option to boot. As a result, externalised storage options becomes a given in large deployments, introducing additional complexities into the equation.

Lastly, just because it is a virtual machine does not imply that it will be more secure than the host OS, nor will it be less secure than the virtual machine's OS, so companies must maintain their better and best practices even within the virtualised space.

Virtualisation grows

According to a BMI-TechKnowledge report looking at IT predictions for 2008, virtualisation is reshaping the infrastructure landscape, as an estimated 19% of physical server deployments during the year will be virtual machine hosts. This will have a negative impact on server processor consumption, squeezing prices and disputing clusters.

Yet, this process will bring a positive impact on storage and infrastructure management software. 2008 will see a strong impact of virtualisation on enterprise IT and the way that IT interacts with business.

In addition, the report said the IT skills shortage will start to bite the industry with strategy increasingly dictating the nature of IT spend moving forward.

Karel Rode is security solutions strategist at CA Africa.


User Comments

All posts are sent to the administrator for review and are published only after approval. ITP.net reserves the right to remove any comment at any time for any reason. Please keep your responses appropriate and on topic.
Name *
( Remmber Me )
Email *
(Your email address will not be published)
City
Country
Subject *
Comment *
Security Code * Code
 


Please click post only once - your comment will not be published immediately.

Related Comment

Ten things you always wanted to know about virtualization management 

Related Feature

Part of the process

CIOs are facing an uphill struggle. More and more demands are being made of IT departments. Budgets are ever-tightening.... 

Related Feature

International Vendors

 


Competitions

Win Lexmark's Superb All-in-One

Ends On Friday, 15 August 2008

Sick of taking your digital snaps to a shop? This all-in-one printer from Lexmark makes photo printing easy, thanks to its range of features.


Advertising Features


Latest Products
Simpletech Duo Pro Drive

Hardware | Storage | July 2008

Look before you switch.

RATING


Western Digital MyBook Studio Edition

Hardware | Storage | July 2008

The MyBook for Macs.

RATING


The Incredible Hulk: The Official Videogame

Games | Console | July 2008

Hulk smaaaaaaaaash!!!

RATING


Sony Handycam HDR-TG1

Hardware | Peripherals | July 2008

Capture moments in HD.

RATING


Technology Jobs
Senior Manager Online Marketing
Location: Dubai, UAE
IT Manager
Location: Dubai, UAE
IT Manager
Location: Dubai, UAE
Manager IT Strategy
Location: Dubai, UAE
Software Assurance Manager
Location: Dubai, UAE

For editorial enquiries contact
Mark Sutton
mark.sutton
@itp.com
To advertise, contact
Ahmad Bashour
+971 4 210 8549
or ahmad.bashour
@itp.com


Arabian Computer News Channel Middle East Channel Middle East - Arabic Charged CommsMEA Network Middle East Windows Middle East Windows Middle East - Arabic ALL ITP TITLES