Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
ComputerWorldNetwork WorldCIO CanadaCIO Canada Governments' ReviewJobUniverse Canada
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Unlock the potential of data with the right data warehouse solutionUnlock the potential of data with the right data warehouse solution read more
IBM Multiform Master Data Management: The evolution of MDM applicationsIBM Multiform Master Data Management: The evolution of MDM applications read more
Closing the data privacy gap: Protecting sensitive data in non-production environmentsClosing the data privacy gap: Protecting sensitive data in non-production environments read more
Yuk it Up
Act to Amend the Copyright Act
Want a copyright law that protects spyware and virus writers? If not, sign our petition to amend Bill C-61
Featured IT Quiz
IT Quiz: Test yourself to see if you have the knowledge to fit into the open source world, and compare yourself with the rest of the respondents
Featured White Papers
This white paper details Intel's current and future energy-saving initiatives to reduce costs and support business goals. Learn how Intel IT is extending its efforts to be a role model enterprise IT organization by supporting the Climate Savers Computing Initiative, which aims to drive a 50 percent reduction in computer-related CO2 emissions worldwide. No registration required.
Sign-Up for
Security
eNewsletter Delivered Weekly
Click here
Page 1 of 1

VMware unveils security developer tool

McAfee VP says VMsafe makes it possible to develop security monitoring software that was not possible in the physical servers. But an Info-Tech analyst warns virtualization can make security more complicated

One of the biggest issues for enterprises considering virtualization is the effect virtual machine deployment could have on their IT security. But with the launch of a new application programming interface, VMware Inc.’s is hoping to address these concerns by enlisting the help of security vendors from around the world.

The VMsafe API will allow vendors to develop security products specifically at the hypervisor level, in order to combat the latest security threats posed by malware, trojans, and keyloggers. At the press time, over 20 security vendors, including McAfee Inc, Symantec Corp. and Checkpoint Software Technologies Ltd., have signed on to build products with the technology.

“With our virtualization technology we have an unprecedented amount of visibility into hardware resources, virtual machine resources and the traffic that goes between them,” said Parag Patel, vice-president of alliances at Palo Alto, Calif.-based VMware. “When fighting against malware threats, you need to compete against the hackers who are always inventing new ways to break security. So we’re trying to take our capabilities and make them available to security vendors and their products.”

One of VMware’s biggest partners in the launch is Santa Clara, Calif.-based McAfee, which demonstrated its use of VMsafe during this week’s VMworld Europe conference.

“We developed a code to leverage the VMsafe API and actually put our McAfee Host Intrusion Protection underneath the operating systems on the virtual machines,” said Jason Yuan, group manager for project management at McAfee. “When we tried to launch a malicious driver, the program alerted us, identified the virus and shut it down before any damage were done.”

Yuan said that in the traditional “Windows” environment, security vendors have not been able to develop monitoring or protection capabilities underneath the operating system. With VMsafe, he said, vendors will be able to provide security protections that were previously not possible in the physical environment.

“We’ve had to fight the “bad guys” at the network level, the application level, even at the kernel level in the operating systems, but the fact remains that we have always been on an even playing field with the hackers,” Yuen said. “This essentially allows us to plug security infrastructure underneath the operating system.”

And it appears VMsafe might even win over security analysts – who have long warned about the dangers virtualization technology can pose to enterprise IT security.

From a security viewpoint, John Sloan, senior research analyst with Info-Tech Research Group, said that because the virtual machines are abstracted from the hardware, virtualization can appear to provide an extra layer of protection.

“On the negative side though, there is the fact that you have a physical machine running a hypervisor full of virtual machines. This brings the added complexity of having to worry about more than one layer of security,” Sloan said.

And because of this, Sloan is hopeful that VMware’s API can be a positive first step for improving virtualization security. With the biggest security headaches around virtualized infrastructure stemming from companies having too many unmanaged virtual machines, Sloan said the API should help address one of the most overlooked areas of virtualization: security management.

“That’s where the security problems come into play when companies replace physical server sprawl with virtual server sprawl,” Sloan said. “Virtualizing all your machines doesn’t do anything to make it easier to manage them from a security standpoint. So, the VMsafe may actually provide a good catch-up in terms of addressing this area at the hypervisor layer.”

David Senf, director of security and software research at IDC Canada, agreed, saying that while sandboxing security measures inside virtual machines is still a must, the fact that vendors can now go underneath the hypervisor should ease the concerns of any enterprise that has been on the fence about virtualization.

“A virtual machine could run firewall software, for example, in a sort of 'software appliance' for additional security, but remember that this only deals with a subset of all potential attacks,” Senf said. “Just because applications are nestled in the seeming safety of a virtual machine does not guarantee security from all threats.”

Senf said that firms need to actively consider additional IT security and policy management issues that come about from desktop and from server virtualization.

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment
Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields



Related Content
Articles

Special Advertising Partners
IDC Case Study: Identity And Access Management Buying Criteria.
IDC analyses IAM buying criteria and deployment at Coppin State University. Coppin State replaces "first generation" IAM solution to obtain benefits needed for today's agile enterprise: ease of integration, rapid deployment, simplified compliance, flexibility.
White Papers
Closing the data privacy gap: Protecting sensitive data in non-production environments
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
Unlock the potential of data with the right data warehouse solution
Once you've made the decision to implement a new data warehouse, you want to make sure you choose the one that's right for your organization. This buyer's guide provides checklists for starting points that you can use when evaluating vendors and their products. Complimentary with registration. Sponsored by IBM.
Prepare for a more efficient SAP implementation: Take data issues off the critical path
This white paper outlines how the Preliminary Data Assessment Appliance (PDAA) from IBM can help address the challenges of integrating data from different operational applications across the enterprise to an SAP platform. Complimentary with registration. Sponsored by IBM.