Open Enterprise News

Open the new about your Business

Enter text paragraph here

Member Login

Lost your password?
Enter 468x60 Ad Code Here

Virtualisation security threatened: XenSource

Enter 468x60 Ad Code Here

XenSource and VMware, two major figures in virtualisation security have warned of challenges facing IT managers in implementing secure virtual environments.

Speaking at the RSA Conference in San Francisco last week, Simon Crosby, chief technology officer for XenSource, said security policies could be broken by misconfiguration.

“Virtualisation can challenge an IT organisation’s infrastructure, which suddenly becomes dynamic,” said Crosby. “You can shift a workload from server A to server B, but if the security policy doesn’t follow, [virtualisation] has broken it. That’s a challenge.”

Crosby warned that throwing random data at the interface between the guest software and the controlling hypervisor could result in successful attacks.

“Attacks known to-date involve fuzzing the emulation interface between the guest and the hypervisor, but they are largely hypothetical,” said Crosby. “Up until now, security has not been a major issue. Threats to the hypervisor are currently minor — there haven’t been many attacks to date, although they will come.”

IT managers should put in place systems to verify that virtual appliances haven’t been modified, including systems that check open-source virtual Just Enough Operating Systems (JEOS) and ’s Hyper-V appliance. “If you have your own [virtual] JEOS update itself that’s a disaster waiting to happen. And Hyper-V has the full attack surface of any operating system, which is not a good thing,” said Crosby.

Crosby said that in general virtualisation reduced the number of points of entry into operating systems, but that vendors relying on kernel access to implement security would run into difficulties. “We reduce the scope of threats because we reduce the attack surface of the operating system,” said Crosby. “The challenge is the way security technologies rely on being inside the operating system to protect against attack.”

Stephen Herrod, chief technology officer for VMware, who was also speaking at the RSA Conference, claimed virtualisation would improve IT security due to fewer third-party drivers introducing vulnerabilities. “The notion that the surface area of attack increases — well, there’s an opportunity to have less layers running in the machine if it doesn’t have a plethora of drivers plugging in and out,” said Herrod.

Infrastructure vulnerabilities introduced through misconfiguration should be a concern for IT professionals, according to Herrod. “Virtual environments can be disruptive [due to] new APIs and security tools to plug into. Security issues can be caused by misconfiguration.”

Herrod added that server virtualisation should be less of a concern than PC virtualisation security. “With server virtualisation the benefits are profound. Security is all centralised and managed from one place: there’s only one image to patch. The challenge is to deliver an end-to end-secure and gorgeous PC experience.”

Tags:

Related posts

Comments are closed.

Recent Posts

Dressing Tips for Realtors

When it comes to Nutrition there is a saying that "You are what you eat". The same may apply to ...

The benefits of Sending Emails to Your Customers

Emails are still an effective marketing instrument in many countries. In this article there are some ways that your business ...

Businesses To Get Extended Support In Firefox 10

It was only six weeks ago, when Mozilla released the Firefox 9. And now it is time for another roll ...

Become a Real Estate Specialist With a Real Estate Bachelor Degree

Are you already working as a Real Estate agent or working in a real estateoffice? Do you want to get a better ...

A new patent battle between Samsung and Apple

Samsung got a new double-hit in its fight with Apple on Tuesday, when the European Union declared that will examine ...

Christina Aguilera, Stevie Wonder perform at Etta James funeral

About 300 mourners remembered legendary singer Etta James on Saturday, Jan 28, as an authentic voice whose velvety vocals bridged ...

Apple’s iBooks Author App Seems To Be Helpful To Many

In spite of Apple’s eminent success, Apple’s latest attention in textbooks creates mixed reactions from Cal State Fullerton students; though, its iBooks Author ...

Why Must You Buy Land In Missouri?

Investing in Missouri can turn out to be best financial decisions of your life. The beautiful land awaits you and ...
We will keep You Updated...
Sign up to receive breaking news
as well as receive other site updates!
Featured Video
Enter 300x250 Ad Code Here
Popular Posts

How to build an open source mainframe in your kitchen

Can you build a mainframe computer at home in your spare time? On your kitchen table? Usi

Twitter and Facebook - Why are they Essential to Your Business?

Thats the importance of social media sites, such as Twitter and Facebook in viral marketin

What You Should Know About the EB-5 Investor Visa Process

This article will address important aspects of the EB-5 Investor Visa Program that you sho

The Vibrance of Boston

Boston, Massachusetts is one of the oldest cities in the United States, and is considered

How the iPad has Made Remote Desktop Software Even Better

Remote Desktop Software, also known as Remote Control Software or Remote Access Software,

Can Oracle be trusted with Java

With Sun gone, will Oracle wreck Java, or set it free? For years Sun dominated the Java wo

Advanced Messaging & Routing with AMQP

Not all message queues are made equal. In the simplest case, a message queue is synonymous

A Bankrupt BP – Worse For The Financial World Than Lehman Brothers?

The BP crisis in the Gulf of Mexico has rightfully been analysed (mostly) from the ecolog

Video Games Increasingly Bringing Players Together Through the Internet

Video games themselves are not something that is completely new. Many of us remember playi

Commodity Update

As of this post September Crude is lower by 1.4% but prices did hold above the 9 day MA. $

British Telecom Files Legal Suit Against Google

British Telecom has filed a lawsuit against Google at a United States court over its Andro

New York area hospitals and physicians using Remote Access Software to help manage their patients.

Area hospitals in New York are using Remote Access Software to manage their patient flow.

Immigrants See Open Doors to America through EB-5 Investor Visa Program

Increasing numbers of foreigners are entering the United States by obtaining the EB-5 gree

Is Investing in Canadian Oil a Good Idea?

When people aren't talking about jobs and the US recession, talk centers around investing

Remote Access and Security: an Issue to Reckon With

How many times have you been to a client's office to make a presentation and forgot to inc