Could Virtualized Servers Present Security Holes?

In spite of the growing popularity of server virtualization, the majority of IT professionals don't consider their virtual environments as secure as the rest of their network operations. That's the conclusion of a recent vendor-sponsored survey of 300 IT managers, security personnel, auditors and administrators. Prism Microsystems sells products for monitoring the security of the IT infrastructure, including hypervisors, the programs that allows multiple operating systems to run on the same piece of hardware.

"2010 State of Virtualization Security Survey," a 14-page report published by the company, cited several vulnerabilities that could exist in an unprotected virtualization layer. This layer encompasses the hypervisor and virtual management applications and can, potentially, "provide unfettered access to all hosted machines on a physical server." Added to that, the authors wrote, "Traffic between virtual machines on the same box never hits the physical network where network monitoring tools such as intrusion prevent/detection systems reside, rendering them ineffective." Also, the report said, log monitoring systems aren't necessarily capturing data at the virtualization layer.

Currently, according to the report's authors, industry experts believe a failure associated with a hypervisor-based attack "is somewhat theoretical." But 58 percent of respondents expressed concern about the potential for a hypervisor to create a single point of entry into multiple machines; 57 percent said they were concerned about the introduction of a new layer that could be attacked; and 54 percent cited "VM sprawl and flexible deployment capabilities" as a potential problem because it could lead to unmonitored or invisible machines.

A comparable number of people--nearly six in 10--reported that they use existing traditional security tools and strategies to secure their virtual environment. Yet slightly more than half of all respondents also said they don't agree that these are sufficient to provide "security insight into all layers of the virtual environment.

Only a fifth of enterprises are using virtual environment-specific security approaches. What's holding the others back is a combination of factors, primarily a lack of budget, a lack of staff expertise, and a lack of support from their security vendors.

"The reality is the money is just not there for specialty virtual security tools. And even if it was available, that approach is incorrect as it creates another silo of un-integrated security data," said Steve Lafferty, Prism's vice president of marketing. "In this environment, IT teams have to get the most out of what they have. This means leveraging solutions that do more with less and provide a single point of control to seamlessly monitor the entire IT infrastructure, from the physical to the virtual."

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • glowing brain, connected circuits, and abstract representations of a book and graduation cap on a light gray gradient background

    Snowflake Launches Program to Upskill 100,000 People in Data and AI

    Cloud data platform Snowflake is embarking on an effort to train and certify more than 100,000 users on its AI Data Cloud by 2027. The One Million Minds + One Platform program will provide Snowflake-delivered courses, training materials, and free access to Snowflake software, at no cost to learners.

  • two abstract humanoid figures made of interconnected lines and polygons, glowing slightly against a dark gradient background

    Microsoft Introduces Copilot Chat Agents for Education

    Microsoft recently announced Microsoft 365 Copilot Chat, a new pay-as-you-go offering that adds AI agents to its existing free chat tool for Microsoft 365 education customers.

  • hand touching glowing connected dots

    Registration Now Open for Tech Tactics in Education: Thriving in the Age of AI

    Tech Tactics in Education has officially opened registration for its May 7 virtual conference on "Thriving in the Age of AI." The annual event, brought to you by the producers of Campus Technology and THE Journal, offers hands-on learning and interactive discussions on the most critical technology issues and practices across K–12 and higher education.

  • Three cubes of noticeably increasing sizes are arranged in a straight row on a subtle abstract background

    A Sense of Scale

    Gardner Campbell explores the notion of scale in education and shares some of his own experience "playing with scale" — scaling up and/or scaling down — in an English course at VCU.