Virtual Security Gets a Boost

How secure is your virtual environment? Recent US-CERT Cyber Security Bulletins list several vulnerabilities for versions of software from VMware that allow attackers to cause denial of service attacks, generate buffer overflows, expose password logging and gain unauthorized privileges that can be used to hijack processes. The exposures have been addressed in patches by the company, but concern has been growing that virtual machines may get less security-related attention from IT staff than physical boxes.

Reflex Security, which develops virtual security software, has enhanced access control functionality and device visibility in its Virtual Security Appliance (VSA). VSA discovers virtual assets and maps them so users can attain a visual view of the virtual infrastructure that is being secured. The new functionality, expected in the next couple of months, will allow users to drill down into the virtualized network infrastructure.

The software profiles the virtual network state, assets, services and communication flows dynamically and provides anti-virus, anti-spyware, network discovery and network policy enforcement services. VSA supports VMware ESX Server, XenSource and Virtual Iron.

"Reflex VSA's ability to expose the virtual network to the security manager and protect it from threats is a proven asset, and the first of its kind in the industry," said Hezi Moore, CTO of Reflex. "Our development is building upon VSA's visibility functionality to add virtual server access control which will invoke permission-based controls for users that can add or remove virtual machines and virtual network components."

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • student reading a book with a brain, a protective hand, a computer monitor showing education icons, gears, and leaves

    4 Steps to Responsible AI Implementation

    Researchers at the University of Kansas Center for Innovation, Design & Digital Learning (CIDDL) have published a new framework for the responsible implementation of artificial intelligence at all levels of education.

  • glowing digital brain interacts with an open book, with stacks of books beside it

    Federal Court Rules AI Training with Copyrighted Books Fair Use

    A federal judge ruled this week that artificial intelligence company Anthropic did not violate copyright law when it used copyrighted books to train its Claude chatbot without author consent, but ordered the company to face trial on allegations it used pirated versions of the books.

  • server racks, a human head with a microchip, data pipes, cloud storage, and analytical symbols

    OpenAI, Oracle Expand AI Infrastructure Partnership

    OpenAI and Oracle have announced they will develop an additional 4.5 gigawatts of data center capacity, expanding their artificial intelligence infrastructure partnership as part of the Stargate Project, a joint venture among OpenAI, Oracle, and Japan's SoftBank Group that aims to deploy 10 gigawatts of computing capacity over four years.

  • laptop displaying a phishing email icon inside a browser window on the screen

    Phishing Campaign Targets ED Grant Portal

    Threat researchers at cybersecurity company BforeAI have identified a phishing campaign spoofing the U.S. Department of Education's G5 grant management portal.