SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Director of technology engineering,Tresys

Director of technology engineering,Tresys

By:  Rafael Ruffolo  On: 31 Jul 2008 For: ComputerWorld Canada Creator

Some IT administrators are placing systems with multiple connections in the DMZ. How to lock up

Many IT administrators out there think that deploying virtual servers will make their VMs bulletproof to security vulnerabilities and malicious attacks. But according to virtualization security experts like Edward L. Haletky, IT managers will be surprised to learn at how much more they can to do protect their virtual infrastructure.

“The biggest security issue right now, as it relates to virtualization, is that people don’t understand what they’re doing,” Haletky, who owns Worchester, Mass.-based AstroArch Consulting Inc. and is also writing a book on virtualization security, said. “The virtualization administrator is not a security administrator. They can’t be because there’s too much to learn. Nor is the virtualization administrator a storage manager and they have to know that as well.”

While virtualization technology is not inherently vulnerable, the wide education gap between security administrators and virtualization administrators often leads to insecure virtualization server deployments. Most virtualization security experts out there — and at this point these experts are very few and far between — recommend virtualization administrators better educate themselves on security, try and implement proper policies and auditing measures for their VMs, and ensure that functionality and content on their VMs are spilt up into isolated operating environments.

More in Network World Canada

Bullet-point Brief: The state of the virtualization market

Isolating your VMs

According to Haletky, virtualization administrators have four networks that they need to worry about: the administrative network, the storage network, the virtual machine network and the VMotion network. Some of the biggest security vulnerabilities, he said, can occur when virtualization administrators don’t isolate these networks.

“Some administrators are putting all four of those networks smack tab in their DMZ (the exposed portion of a corporate network, which might contain Web and other networked servers), when only one should go there,” he said. Haletky said there are hard and fast rules that govern what IT can do within the DMZ — first and foremost being a ban on systems with more than one network connection. Haletky said the same rule should also apply to virtual servers and he advised IT administrators to keep them as far away from the DMZ as possible.

David Senf, director of security and software research at IDC Canada, agreed. “To avoid mixing security policies and preventing things like escalation of privileges, some IT departments won’t allow VM sessions in their DMZ to reside on hosts behind the DMZ, for example,” he said

John Sloan, senior research analyst at London, Ont.-based Info-Tech Research Group, said that administrators can use network isolation by grouping VMs together in specific security zones. “You could have machines that are hived off from other machines and given varying levels of security,” he explained.


Sign up for our Newsletters












Print |  Views: 1178   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Rafael Ruffolo Rafael Ruffolo was a senior writer for ComputerWorld Canada from 2006 to 2011. He was the winner of a Kenneth R. Wilson award for business journalism in 2009.

Related Content

How does your garden grow ?
How does your garden grow ?Virtualization is taking root in datacentres across the country, but it needs the right kind of nurturing to ensure that it thrives in your IT environment. Here are some tips for developing a virtualization green thumb
Virtual networking practices up for debate
Virtual networking practices up for debateThe virtual network begins where the physical network ends at the virtualization host. The network adapters in the physical host are bridged to the virtualization layer. What happens next depends on the virtualization host in use
Lack of virtual firewalls is a hazard, says analyst
Lack of virtual firewalls is a hazard, says analystWhen multiple applications are crowded into one server, the potential for trouble from new attacks increases, according to an expert from research firm Gartner. Greg Young offers some alternatives
Putting the Cart before the Horse
cisco has come forward with a new vision for the data center. this may really be what i have maintained for the last 15+ years. the future will happen when the “computer is really in the network.” this is cisco’s first big shot in a war to control the data center of the future. this strategy, cisco's data c
Wireless LAN security vs. convenience - walking the tightrope
by joaquim p. menezes - “security vs. ease of use” – is a conundrum a lot of network managers face when it comes to wir
blog comments powered by Disqus