SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

The challenge of securing virtualization operations

The challenge of securing virtualization operations

By:  Andreas Antonopoulos  On: 07 Sep 2008 For: Network World (US) (DW) Creator

The old management mantra is "you can't manage what you don't measure." The mantra for security operations in a virtual environment is "you can't secure it if you can't even find it"

I have been very interested in virtualization security since early 2004 and it now seems like it has become a mainstream topic. Most of the focus however is on securing the technology of virtualization (the hypervisor) and providing virtualized security (usually as virtual appliances).

My focus nowadays is more on the operational impact of virtualized infrastructure and by extension the impact on security operations. After all, security controls (technology) are essential but without operational controls (people) they are not sufficient. So what is the operational impact of virtualization?

Virtualization technology is being applied across multiple IT silos: servers, applications, storage and networks. In every one of these domains, virtualization hides the physical infrastructure behind an abstraction layer and provides encapsulation of logical instances. When you're looking for the root cause of a fault or a security alert you have to lift the veil and see behind the virtualization layer. This sounds a lot easier than it is in practice.

On top of the abstraction layer, virtual infrastructures are often very dynamic. Live migration technology (such as VMotion or XenMotion) allows virtual machines to move from host to host in near-real-time. On top of live migration there are other layered features like dynamic resource pools and high availability clusters. Together, these create an environment where virtual machines may move automatically to rebalance a load, reduce power consumption or in reaction to a hardware failure. Similar dynamic moves may be occurring in a virtual storage environment and (storage re-allocation) and in the network (load balancing, virtual LAN allocation). In a large virtual server pool this could create an almost constantly changing environment.

Furthermore, security operations must deal with an environment where servers come into existence and are decommissioned at an accelerated rate. Sine virtualization allows admins to virtually build, rack, run and decommission a server in a matter of minutes, the life cycle of a server becomes shorter. Servers evolve from being enduring and tangible to fleeting and ethereal. How do you troubleshoot or forensically analyze a server that only existed for a day? Where do you find its logs, its configuration?

Security operations in a virtual environment involve:

* Piercing the veil (correlating events above the abstraction layer with events below).

* Synchronizing timestamps globally.

* Collecting logs and configuration changes centrally.

* Tracking virtual machine identities independently of IP address.

* Tracking virtual machine life cycle and genealogy.

* Maintaining libraries of patched and hardened virtual machine images.

We have technology to deal with most of these problems and doubtless we will see startups emerge to address problems that are new and unique to this environment. Many of the challenges are only noticeable once virtualization technology has been adopted in production and deployed broadly in a data centre. They surely should be discussed at the early planning stages instead. The old management mantra is "you can't manage what you don't measure". The mantra for security operations in a virtual environment is "you can't secure it if you can't even find it."


Sign up for our Newsletters












Print |  Views: 663   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Andreas Antonopoulos Andreas Antonopoulos is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

How does your garden grow ?
How does your garden grow ?Virtualization is taking root in datacentres across the country, but it needs the right kind of nurturing to ensure that it thrives in your IT environment. Here are some tips for developing a virtualization green thumb
10 virtualization vendors to watch in 2008
10 virtualization vendors to watch in 2008Now that you're knee-deep in virtualization, what products will help you manage and secure it? These 10 virtualization vendors should be on your radar screen. And, Canada's own Platform Computing is part of that list.
Make the business case for storage virtualization
Make the business case for storage virtualizationVendors claim storage the technology helps reduce costs through better utilization of your hardware, but three in four respondents to a recent IDC Canada survey said they see no need for it
Does Virtualization Equal ‘Bullet Proof’?
virtualization has been available to the it world for more than four decades, yet it has still not really taken off in the multi system environment.  many vendors are pushing this approach to deploying ‘flexible technology’, yet it still has not emerged beyond the ‘glass house’ of the data centers or server closets.  ibm i

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.