Securing your virtualized environment

Protecting virtualized resources requires a mix of old and new security tactics.

Virtualization promises to make IT departments more flexible, more efficient and -- perhaps most crucial in these tough times -- more frugal. But one advantage the technology doesn't provide is an escape from the need for strong security measures.

As soon as he began planning his Novell virtualization project, Noah Broadwater realized that he was looking at an initiative that would require both a continuation of existing security practices and an analysis of any perils that might be created by the new technology.

"It was evident that virtualization demanded a close look," says Broadwater, who is vice president of information services at New York-based children's media producer Sesame Workshop. "Above all, we had to make sure that we would be secure on all fronts."

Neil MacDonald, an analyst at Gartner Inc., says that virtualization is opening new doors for IT departments as well as for people who seek to tamper with critical data and services.

"Adopters can expect that virtualized software, like hypervisor software, will be attack targets," he says. "Therefore, virtualization security planning should be addressed at a project's inception."

Crash and Learn

With IT departments in today's crashing economy being asked to do more with less, virtualization's lure is becoming increasingly irresistible. But as some departments rush headlong toward the technology in an effort the stretch scarce dollars, the temptation arises to skimp on security.

Many thrifty managers believe that the same technologies currently used to protect conventional physical servers can simply be extended to virtualized environments. But MacDonald says that's a potentially calamitous assumption. He notes that the unwary could be trapped by threats in several areas, including software, administration, mobility, the operating system and network visibility. "There need to be policies to address these issues," he adds.

Broadwater takes some common-sense defensive steps, such as using firewall controls to limit user access and running a full array of security protocols and checks on each virtual server. In addition, Broadwater says he depends on his virtualization software vendor, Novell Inc., to supply a product that's resistant to intrusions and attacks. He says he worries about "holes in the virtualization software itself -- kernel attacks, someone attacking the host module or one of my guys making a mistake against the host server -- and then making sure that the full virtualization software is actually secure and is patched."

More about: Enterprise Management Associates, etwork, Gartner, Lionbridge Technologies, Microsoft, Novell, Oracle, VMware
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the Computerworld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Whitepapers
All whitepapers
Sign up now to get free exclusive access to reports, research and invitation only events.
Featured Download
/downloads/product/138/driverscanner-2010/

DriverScanner 2010

DriverScanner scans your computer and provides you with a list of drivers that need to be updated. All you have to do, then, is simply ...

Computerworld newsletter

Join the most dedicated community for IT managers, leaders and professionals in Australia