|
||||
|
While server virtualization is exploding into data centers around the world, the technology for securing virtual environments is lagging behind. It's a fact likely to give some organizations that have gone down the virtualization path some very acute server security headaches, according to James Collinge, product line management director at network security solution provider TippingPoint, a division of HP. Collinge expressed this view at the Infosecurity Europe 2010 conference in London earlier this year. To get some perspective, at least 16 percent of all enterprise workloads were running in virtual servers in the latter part of 2009 according to Gartner, but this number is predicted to grow to 50 percent -- or around 58 million x86-based virtual servers -- by 2012. But Gartner predicts that some 60 percent of those virtual servers will be less secure than the physical machines they replace. Forrester Research also points out that 98 percent of organizations that use some form of virtualization are using VMware virtualization technologies. That means that if a zero-day exploit is discovered for VMware, it is likely to be more interesting to hackers than a similar one for a given mail, web, or DNS server would be. Why will virtualized servers be less secure than the physical machines they replace? Some of the reasons for this lower level of server security that Collinge mentioned include:
In terms of actual threats to a virtualized environment, these fall into a number of categories -- centered on the hypervisor -- such as:
What all this goes to show is that when organizations introduce a virtualized environment, they introduce a new mission-critical element: the hypervisor. Since successful attacks on hypervisors can lead to the compromise of all the hosted workloads -- and since successful attacks on individual virtualized workloads can also lead to a compromise of the hypervisor -- the organization's hypervisors should be considered mission-critical and secured appropriately, Collinge said. In a traditional IT environment, network traffic can be monitored, inspected and filtered using a range of server security systems to try to detect malicious activity. But a problem with virtualized environments is that local communications between virtual servers that run through a virtual switch is largely invisible: It never "hits the wire" where it can be monitored in the normal way. There's only one solution to that, Collinge said he believes. "Visibility and control of VM-to-VM traffic flows must be established." A compounding problem is the separation of duties that often occurs in a virtualized data center. Server and operations teams are often responsible for the provisioning and management of virtual switches. Little or no integration with tools and security controls is implemented. For the network and security teams, this leads to a lack of visibility to perform configuration auditing, and it makes it difficult to detect topology and configuration changes, Collinge said, noting, "Network and security teams must regain visibility at the access layer." Collinge cited three ways to achieve this: 1. Hardware-Based ApproachThis involves forcing traffic between ESX hosts to be inspected by an intrusion prevention system (IPS). The system Collinge describes has each ESX host configured with a unique ingress/egress VLAN pair, with the IPS configured with VLAN translation to configure each ingress VLAN and egress VLAN pair. This ensures all VM-to-VM traffic is sent out "over the wire" to the IPS for inspection, and only clean traffic is allowed to travel between each ingress/egress VLAN pair. A disadvantage of this approach is that it can be very costly to replicate this at multiple data centers and disaster recovery sites. 2. Fully Virtualized ApproachWith this method, a virtual IPS and firewall is implemented on each ESX host, with policy configured on each virtual machine to decide what traffic should be inspected. This "bump in the wire" approach ensures all allowed intra-virtual machine traffic is inspected, and it has the bonus that when virtual machines are moved between physical hosts, the security policies move with them The downside, however, is there can be significant performance penalties with this architecture. 3. Hybrid ApproachThis is an alternative way of doing things that largely mitigates the performance issues of the fully virtualized approach. It involves running a virtual redirector on each virtual machine, configured with a policy on what traffic should be redirected -- to a physical IPS -- for inspection. The IPS allows only inspected and clean re-directed traffic to travel between virtual machines. So which is the best approach? Collinge says that what best suits a given organization will depend on its goals and budget, as well as its attitude to risk. Some successful solutions will probably involve a combination of two of these three approaches. The good news is that building and implementing these types of solutions is likely to become easier in the near future, Collinge said, as security companies develop a larger range of products that provide the necessary functionality. |
||||

|
The Internet is designed to route around network problems, which improves the reliability and performance of public clouds. Hybrid clouds, however, can bog down within the data center if they are using traditional Ethernet. Ethernet Fabric architectures, on the other hand, are ideal for hybrid clouds.
|
|
As businesses look to cut computing costs, improve service levels and adopt new delivery mechanisms such as cloud computing, it is causing them to rethink their network architecture.
|
|
Your network may not be ready for the cloud. Classic Ethernet switches will have trouble supporting cloud computing and the data centers of tomorrow because they're hierarchical, inefficient and they don't scale.
|

|
Learn from Mark Fabbi, Gartner, and Brocade how a flatter, more simplified network architecture supports a cloud-based model.
|
|
Surprisingly, 75 percent of respondents to a Forrester Research survey said that deploying server virtualizations means their business has a private cloud. Download this report to learn more about what's required in a next-generation data center that supports virtualization and the cloud.
|
|
Ethernet fabrics reduce complexity and costs in a virtual data center, while providing the ultimate in scalability, performance and application mobility. Download this paper to better understand how Brocade's Virtual Cluster Switching enables organizations to simplify their network architecture while dramatically reducing operating expenses.
|