LAS VEGAS — Within the first 24 hours after the announcement of Osama Bin Laden’s death, 100 million spam e-mails were sent out around the world. Attackers are trying to get into corporate networks and they’ll try any number of techniques to do so, and one way is by taking advantage of these types of events.
But do these threats change in a virtual environment? In many ways the threats are the same, and companies need to do the same things to protect their data. “But adding virtualization adds a whole different layer,” said Francis deSouza, senior vice-president of Symantec’s enterprise security group, during the company’s Symantec Vision conference.
Virtualization, combined with increasing amounts of data, has created unique demands on the data centre, and companies have to backup and secure higher density virtual environments.
Companies initially try to treat virtual deployments like physical environments, said Stephen Herrod, VMware’s chief technology officer. The problem is, many customers have 50 to 100 workloads on the same server, so they can’t run backups in the same old way or they’ll have efficiency and productivity issues. So VMware is working with Symantec to hash out some of these issues.
At the conference, Symantec outlined its plan to “modernize” the way organizations backup, recover and discover their data. Now available, its V-Ray technology is being embedded into Symantec NetBackup and Backup Exec to give IT administrators visibility into their virtual environments.
Symantec says the technology provides transparency of backup images across physical and virtual environments with a single view, making it easier to protect systems and applications. The idea is to minimize labour-intensive file and application recovery efforts and drive down backup storage costs through de-duplication across physical and virtual systems.
“Security is an afterthought in a virtualized environment,” said Lauren Whitehouse, senior analyst with ESG, a Milford, Mass.-based analyst firm. “Virtualization breaks what you have in place. It introduces new risks. [Companies] should be thinking about protecting their environment from day one.”
If they run a virus scan on a virtual machine, for example, it can wreak havoc with the system. Or if four virtual machines all start backing up at the same time, it can kill any performance improvements associated with that virtual environment.
According to ESG, the hypervisor is a common gateway for attackers. In a virtualized environment you want everything sharing common resources, said Whitehouse, but from a security point of view this is not necessarily a good thing. Also, virtual sprawl could create a large target attack, and virtual assets are often more difficult to monitor.