Skip the navigation

Drawn to Vegas by Virtualization

At the Interop show, our manager got the scoop on the security implications of virtualization and CMDB.

By Mathias Thurman
June 11, 2007 12:00 PM ET

Computerworld - A couple of weeks ago, my boss asked me if I would consider going to Interop. Its my custom to attend the SANS and RSA security conferences each year. But my boss was offering to get me out of the office for a week, in Las Vegas in May. How could I resist? I booked my flight and hotel within the hour.

Conferences can be overwhelming, and Interop had a lot of content on the schedule related to information security, possibly more than for any other discipline. You can feel like a kid in a candy store  you want to be everywhere at once, taking it all in. My strategy is to focus on a couple of topics and then learn as much as I can about them. For Interop, I decided that the topics would be virtualization and configuration management.

Virtual Enthusiasm

Virtualization is nothing new, having been used on mainframes for years, but its a hot topic at my company right now. We are aggressively virtualizing server environments for almost every new application we deploy, and were migrating a lot of existing applications to such environments.

Of course, virtualization carries security implications. For example, in typical architectures for Web-based applications, the Web, application and database servers are installed on separate pieces of hardware, each running its own operating system, locked down according to the security baseline and patched appropriately. There are also virtual LANs and firewalls to segment each resource. Firewalls configured for a rule of least privilege ensure that the relationships between the Web server, application and database servers are restricted. Usually, there would be no relationship between the Web server and the back-end database server, since the application server would act as a sort of proxy between them. The setup ensures that a compromised Web server wont give a bad guy the ability to launch an attack directly against the database server.

Things are different in a virtual environment. The Web, application and database servers might all be installed on the same piece of iron. The cost savings are hard to say no to, and you might even get a performance boost. But, as speakers noted at Interop, if you dont have controls in place to provide the needed separation of duties within the virtual environment, you could be in trouble.

At Interop, there was a lot of talk about the virtualization concept of the master control server, sometimes called a hypervisor. This is the control center for the virtual environments living on a single piece of hardware. Anyone who compromised the hypervisor would essentially be in control of many of the resources that the virtual environments living on that piece of hardware need access to. In other words, lock down the hypervisor to restrict access by role, or face the consequences.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Driving Secure Enterprise File Sharing and Syncing in the Enterprise
GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
The Enterprise File Sharing Option
Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
Security Strategies to Virtualizing Internet-Facing Applications
The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
Cloud Security Planning Guide
Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
Cloud Security Vendor Round Table
This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions...
All Security White Papers
Security Webcasts
Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
BlackBerry PlayBook OS 2.0 Security Overview
The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs